Jira δÊÚȨ SSRF Îó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-09-24Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-8451£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º6.5
Ó°Ïì°æ±¾
Jira < 8.4.0
Îó²î¸ÅÊö
Atlassian JiraÊǰĴóÀûÑÇAtlassian¹«Ë¾µÄÒ»Ì×ȱÏݸú×ÙÖÎÀíϵͳ¡£¡£¡£¡£¡£¸ÃϵͳÖ÷ÒªÓÃÓÚ¶ÔÊÂÇéÖÐÖÖÖÖÎÊÌ⡢ȱÏݾÙÐиú×ÙÖÎÀí¡£¡£¡£¡£¡£
Jira µÄ /plugins/servlet/gadgets/makeRequest ×ÊÔ´±£´æ SSRF Îó²î£¬£¬£¬£¬£¬Ôµ¹ÊÔÓÉÔÚÓÚ JiraWhitelist Õâ¸öÀà±£´æÂ߼ȱÏÝ¡£¡£¡£¡£¡£ÔÚСÓÚ 8.4.0 µÄ Jira °æ±¾ÖУ¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÒÔ Jira ЧÀͶ˵ÄÉí·Ý»á¼ûÄÚÍø×ÊÔ´£¬£¬£¬£¬£¬²¢ÇÒ¸ÃÎó²îÎÞÐèÈÎºÎÆ¾Ö¤¼´¿É´¥·¢¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
https://jira.atlassian.com/browse/JRASERVER-69793
²Î¿¼Á´½Ó