Jira δÊÚȨ SSRF ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-09-24

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-8451£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º6.5


Ó°Ïì°æ±¾


Jira < 8.4.0 


·ì϶¸ÅÊö


Atlassian JiraÊǰĴóÀûÑÇAtlassian¹«Ë¾µÄÒ»Ì×ȱµã¸ú×ÙÖÎÀíϵͳ¡£¡£¡£¡£¡£¡£¸ÃÏµÍ³ÖØÒªÓÃÓÚ¶Ô¹¤×÷Öи÷ÀàÎÊÌ⡢ȱµã½øÐиú×ÙÖÎÀí¡£¡£¡£¡£¡£¡£


Jira µÄ /plugins/servlet/gadgets/makeRequest ×ÊÔ´´æÔÚ SSRF ·ì϶£¬£¬£¬£¬£¬£¬£¬Ô­ÒòÔÚÓÚ JiraWhitelist Õâ¸öÀà´æÔÚÂß¼­È±µã¡£¡£¡£¡£¡£¡£ÔÚÓ×ÓÚ 8.4.0 µÄ Jira °æ±¾ÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÒÔ Jira ·þÎñ¶ËµÄÉí·Ý½Ó¼ûÄÚÍø×ÊÔ´£¬£¬£¬£¬£¬£¬£¬²¢ÇҸ÷ì϶ÎÞÐèÈκÎÍ´´¦¼´¿É´¥·¢¡£¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º

https://jira.atlassian.com/browse/JRASERVER-69793 


²Î¿¼Á´½Ó


https://jira.atlassian.com/browse/JRASERVER-69793