Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-66642

Server Side Request Forgery(SSRF) in the Jira Trello importer - CVE-2017-16865

    XMLWordPrintable

Details

    Description

      The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF). When running in an environment like Amazon EC2, this flaw maybe used to access to a metadata resource that provides access credentials and other potentially confidential information.

      Attachments

        Activity

          People

            Unassigned Unassigned
            security-metrics-bot Security Metrics Bot
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: