MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the plaintext OAuth fallback file containing refresh and access tokens is written with permissions inherited from the process umask. Under com
| 厂商 | 产品 | 版本范围 | 状态 |
|---|---|---|---|
| sooperset | mcp-atlassian | < 0.22.0 |
affected |
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| sooperset | mcp-atlassian | < 0.22.0 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC| CVE-2026-77244 | 10.0 CRITICAL | [mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier acce |
| CVE-2026-77254 | 9.1 CRITICAL | MCP Atlassian: Unauthenticated HTTP MCP requests can use globally configured Jira and Conf |
| CVE-2026-77274 | 8.8 HIGH | MCP Atlassian: SSRF Protection Bypass |
| CVE-2026-77243 | 8.8 HIGH | MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass |
| CVE-2026-77262 | 8.6 HIGH | MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP to |
| CVE-2026-77248 | 8.6 HIGH | MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, |
| CVE-2026-77255 | 8.6 HIGH | MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue |
| CVE-2026-77271 | 8.3 HIGH | MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (by |
| CVE-2026-77247 | 8.3 HIGH | MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unres |
| CVE-2026-77260 | 8.3 HIGH | MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment |
| CVE-2026-77257 | 8.3 HIGH | MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths |
| CVE-2026-77267 | 8.3 HIGH | mcp-atlassian has an incomplete SSRF remediation |
| CVE-2026-77251 | 8.3 HIGH | MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project con |
| CVE-2026-77259 | 7.7 HIGH | MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of |
| CVE-2026-77258 | 7.7 HIGH | MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_saf |
| CVE-2026-77242 | 7.5 HIGH | MCP Atlassian: Incomplete fix for CVE-2026-27826: DNS rebinding bypasses SSRF validation ( |
| CVE-2026-77246 | 7.4 HIGH | MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment U |
| CVE-2026-77253 | 7.1 HIGH | MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local |
| CVE-2026-77261 | 7.1 HIGH | MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication br |
| CVE-2026-77270 | 6.5 MEDIUM | MCP Atlassian: Arbitrary File Read via Upload Attachment Tools |
显示前 20 条,共 29 条。 查看全部 → →
暂无评论