Jira δÊÚȨ SSRF Îó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-09-24Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-8451£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬CVSS·ÖÖµ£º6.5
Ó°Ïì°æ±¾
Jira < 8.4.0
Îó²î¸ÅÊö
Atlassian JiraÊǰĴóÀûÑÇAtlassian¹«Ë¾µÄÒ»Ì×ȱÏݸú×ÙÖÎÀíϵͳ¡£¡£¡£¸ÃϵͳÖ÷ÒªÓÃÓÚ¶ÔÊÂÇéÖÐÖÖÖÖÎÊÌ⡢ȱÏݾÙÐиú×ÙÖÎÀí¡£¡£¡£
Jira µÄ /plugins/servlet/gadgets/makeRequest ×ÊÔ´±£´æ SSRF Îó²î£¬£¬Ôµ¹ÊÔÓÉÔÚÓÚ JiraWhitelist Õâ¸öÀà±£´æÂ߼ȱÏÝ¡£¡£¡£ÔÚСÓÚ 8.4.0 µÄ Jira °æ±¾ÖУ¬£¬¹¥»÷Õß¿ÉÒÔÒÔ Jira ЧÀͶ˵ÄÉí·Ý»á¼ûÄÚÍø×ÊÔ´£¬£¬²¢ÇÒ¸ÃÎó²îÎÞÐèÈÎºÎÆ¾Ö¤¼´¿É´¥·¢¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£
ÐÞ¸´½¨Òé
https://jira.atlassian.com/browse/JRASERVER-69793
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ