CVE-2017-9506
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server Side Request Forgery (SSRF).
- Affected products
- Oauth Plugin, Jira, Jira Work Management
- Atlassian Oauth
- = 1.3.0, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, 1.3.9, 1.3.10, 1.4.0, 1.4.1, 1.5.0, 1.6.0, 1.6.1, 1.7.0, 1.8.0, 1.8.1, 1.8.2, 1.8.3, 1.8.4, 1.8.5, 1.9.0, 1.9.1, 1.9.2, 1.9.3, 1.9.4, 1.9.5, 1.9.6, 1.9.7, 1.9.8, 1.9.9, 1.9.10, 1.9.11, 2.0.0, 2.0.1, 2.0.2, 2.0.3
- Fix
- Available
- CVSS 3.0
- 6.1 MEDIUM
- EPSS
- 71.6% (99th percentile)
- Weakness
- CWE-918
- NVD status
- Modified
- Published
- 2017-08-23
CVE-2017-9506 at NVD
3 known exploits for CVE-2017-9506
Proof-of-concept code and exploit modules indexed by Sploitus