Atlassian OAuth Plugin是澳大利亚Atlassian公司的一款用于访问个人Atlassian软件数据的授权插件。 Atlassian OAuth Plugin中的IconUriServlet存在安全漏洞。远程攻击者可利用该漏洞访问内部网络资源或执行跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Atlassian | Atlassian OAuth Plugin | From version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4. | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2017-9506 - SSRF | https://github.com/random-robbie/Jira-Scan | POC Details |
| 2 | CVE-2017-9506 | https://github.com/pwn1sher/jira-ssrf | POC Details |
| 3 | Atlassian Jira XSS attack via Server Side Request Forgery (SSRF). | https://github.com/labsbots/CVE-2017-9506 | POC Details |
| 4 | The Atlassian Jira IconUriServlet of the OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 contains a cross-site scripting vulnerability which allows remote attackers to access the content of internal network resources and/or perform an attack via Server Side Request Forgery. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2017/CVE-2017-9506.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet