CVE-2017-9506
CVE-2017-9506
Vexday Risk Score
40Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS —EPSS 71.6%KEV nãoPoC —Nuclei simMetasploit —Patch —
Lifecycle
23 Aug 2017Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server Side Request Forgery (SSRF).
Affected products
Atlassian · Atlassian OAuth PluginWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://dontpanic.42.nl/2017/12/there-is-proxy-in-your-atlassian.htmlhttps://ecosystem.atlassian.net/browse/OAUTH-344https://medium.com/bugbountywriteup/piercing-the-veil-server-side-request-forgery-to-niprnet-access-171018bca2c3https://twitter.com/ankit_anubhav/status/973566620676382721https://twitter.com/Zer0Security/status/983529439433777152