Jira δÊÚȨ SSRF Îó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-09-24Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-8451£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬CVSS·ÖÖµ£º6.5
Ó°Ïì°æ±¾
Jira < 8.4.0
Îó²î¸ÅÊö
Atlassian JiraÊǰĴóÀûÑÇAtlassian¹«Ë¾µÄÒ»Ì×ȱÏݸú×ÙÖÎÀíϵͳ¡£¡£¡£¡£¸ÃϵͳÖ÷ÒªÓÃÓÚ¶ÔÊÂÇéÖÐÖÖÖÖÎÊÌ⡢ȱÏݾÙÐиú×ÙÖÎÀí¡£¡£¡£¡£
Jira µÄ /plugins/servlet/gadgets/makeRequest ×ÊÔ´±£´æ SSRF Îó²î£¬£¬£¬£¬Ôµ¹ÊÔÓÉÔÚÓÚ JiraWhitelist Õâ¸öÀà±£´æÂ߼ȱÏÝ¡£¡£¡£¡£ÔÚСÓÚ 8.4.0 µÄ Jira °æ±¾ÖУ¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÒÔ Jira ЧÀͶ˵ÄÉí·Ý»á¼ûÄÚÍø×ÊÔ´£¬£¬£¬£¬²¢ÇÒ¸ÃÎó²îÎÞÐèÈÎºÎÆ¾Ö¤¼´¿É´¥·¢¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£
ÐÞ¸´½¨Òé
https://jira.atlassian.com/browse/JRASERVER-69793
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ