Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-53362

The bundled Atlassian OAuth plugin allows arbitrary HTTP requests to be proxied - CVE-2017-9506

      The version of the bundled Atlassian OAuth plugin was vulnerable to Server Side Request Forgery (SSRF). This allowed a XSS and or a SSRF attack to be performed. More information about the Atlassian OAuth plugin issue see https://ecosystem.atlassian.net/browse/OAUTH-344 . When running in an environment like Amazon EC2, this flaw can used to access to a metadata resource that provides access credentials and other potentially confidential information.

      Workaround for Confluence - In case you can't upgrade yet to 6.1.3:

      1. Shutdown Confluence.
      2. Go to <Confluence-Installation-Directory>/confluence/WEB-INF/atlassian-bundled-plugins and find the atlassian-oauth-service-provider-plugin-2.0.2.jar file.
      3. Delete it.
      4. Download below file, which is the atlassian-oauth-service-provider-plugin-2.0.4.jar file for Confluence:
        atlassian-oauth-service-provider-plugin-2.0.4.jar
      5. Paste it inside <Confluence-Installation-Directory>/confluence/WEB-INF/atlassian-bundled-plugins folder.
      6. Clear plugin cache.
      7. Bring Confluence back online.

            [CONFSERVER-53362] The bundled Atlassian OAuth plugin allows arbitrary HTTP requests to be proxied - CVE-2017-9506

            John Bartelt added a comment - - edited

            Is there a workaround for confluence 5.8.18?  It has atlassian-oauth-service-provider-plugin-1.9.10.jar .

            Edited:  Where do I find version 1.9.12?

             

            John Bartelt added a comment - - edited Is there a workaround for confluence 5.8.18?  It has atlassian-oauth-service-provider-plugin-1.9.10.jar . Edited:  Where do I find version 1.9.12?  

            Workaround for Confluence - In case you can't upgrade yet to 6.1.3:

            1. Shutdown Confluence.
            2. Go to <Confluence-Installation-Directory>/confluence/WEB-INF/atlassian-bundled-plugins and find the atlassian-oauth-service-provider-plugin-2.0.2.jar file.
            3. Delete it.
            4. Download below file, which is the atlassian-oauth-service-provider-plugin-2.0.4.jar file for Confluence:
              atlassian-oauth-service-provider-plugin-2.0.4.jar
            5. Paste it inside <Confluence-Installation-Directory>/confluence/WEB-INF/atlassian-bundled-plugins folder.
            6. Clear plugin cache.
            7. Bring Confluence back online.

            Marcelo Horlle added a comment - Workaround for Confluence - In case you can't upgrade yet to 6.1.3: Shutdown Confluence. Go to <Confluence-Installation-Directory>/confluence/WEB-INF/atlassian-bundled-plugins and find the atlassian-oauth-service-provider-plugin-2.0.2.jar file. Delete it. Download below file, which is the atlassian-oauth-service-provider-plugin-2.0.4.jar file for Confluence: atlassian-oauth-service-provider-plugin-2.0.4.jar Paste it inside <Confluence-Installation-Directory>/confluence/WEB-INF/atlassian-bundled-plugins folder. Clear plugin cache . Bring Confluence back online.

            CVSS v3 score: 6.1 => Medium severity

            Exploitability Metrics

            Attack Vector Network
            Attack Complexity Low
            Privileges Required None
            User Interaction Required

            Scope Metric

            Scope Changed

            Impact Metrics

            Confidentiality Low
            Integrity Low
            Availability None

            David Black added a comment - CVSS v3 score: 6.1 => Medium severity Exploitability Metrics Attack Vector Network Attack Complexity Low Privileges Required None User Interaction Required Scope Metric Scope Changed Impact Metrics Confidentiality Low Integrity Low Availability None

              Unassigned Unassigned
              dblack David Black
              Affected customers:
              0 This affects my team
              Watchers:
              8 Start watching this issue

                Created:
                Updated:
                Resolved: