漏洞描述
The Atlassian Jira IconUriServlet of the OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 contains a cross-site scripting vulnerability which allows remote attackers to access the content of internal network resources and/or perform an attack via Server Side Request Forgery.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
dontpanic.42.nlhttp://dontpanic.42.nl/2017/12/there-is-proxy-in-your-atlassian.html↗ecosystem.atlassian.nethttps://ecosystem.atlassian.net/browse/OAUTH-344↗medium.comhttps://medium.com/bugbountywriteup/piercing-the-veil-server-side-request-forgery-to-niprnet-access-171018bca2c3↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2017-9506↗github.comhttps://github.com/d4n-sec/d4n-sec.github.io↗