Jira δÊÚȨ SSRF Îó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-09-24

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-8451£¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬ £¬£¬£¬£¬CVSS·ÖÖµ£º6.5


Ó°Ïì°æ±¾


Jira < 8.4.0 


Îó²î¸ÅÊö


Atlassian JiraÊǰĴóÀûÑÇAtlassian¹«Ë¾µÄÒ»Ì×ȱÏݸú×ÙÖÎÀíϵͳ¡£¡£¡£¡£¡£¸ÃϵͳÖ÷ÒªÓÃÓÚ¶ÔÊÂÇéÖÐÖÖÖÖÎÊÌ⡢ȱÏݾÙÐиú×ÙÖÎÀí¡£¡£¡£¡£¡£


Jira µÄ /plugins/servlet/gadgets/makeRequest ×ÊÔ´±£´æ SSRF Îó²î£¬ £¬£¬£¬£¬Ôµ¹ÊÔ­ÓÉÔÚÓÚ JiraWhitelist Õâ¸öÀà±£´æÂß¼­È±ÏÝ¡£¡£¡£¡£¡£ÔÚСÓÚ 8.4.0 µÄ Jira °æ±¾ÖУ¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÒÔ Jira ЧÀͶ˵ÄÉí·Ý»á¼ûÄÚÍø×ÊÔ´£¬ £¬£¬£¬£¬²¢ÇÒ¸ÃÎó²îÎÞÐèÈÎºÎÆ¾Ö¤¼´¿É´¥·¢¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬ £¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º

https://jira.atlassian.com/browse/JRASERVER-69793 


²Î¿¼Á´½Ó


https://jira.atlassian.com/browse/JRASERVER-69793