Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-73811

IDOR (Insecure direct object references) in Jira 8.13.10

XMLWordPrintable

      We have found during testing that by sending a fake header with a domain name (supplying as a suffix (i.e. attack.eu)) into the Host header field, the web server processes the input to send the request to an attacker-controlled host that resides at the supplied domain, and not to an internal virtual host that resides on the web server.

      Affected versions:

      • 8.13.10

      Earlier fixed versions:

      • 7.13.16
      • 8.5.7
      • 8.9.2
      • 8.10.1
      • 8.11.0

            4e432536cf93 Karol Skwierawski
            f956e0e022e9 skavatekar
            Votes:
            2 Vote for this issue
            Watchers:
            14 Start watching this issue

              Created:
              Updated: