Vulnerability CVE-2017-9506


Published: 2017-08-23   Modified: 2017-08-24

Description:
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server Side Request Forgery (SSRF).

Type:

CWE-918

CVSS2 => (AV:N/AC:M/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
2.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Atlassian -> Oauth 

 References:
http://dontpanic.42.nl/2017/12/there-is-proxy-in-your-atlassian.html
https://ecosystem.atlassian.net/browse/OAUTH-344
https://medium.com/bugbountywriteup/piercing-the-veil-server-side-request-forgery-to-niprnet-access-171018bca2c3
https://twitter.com/ankit_anubhav/status/973566620676382721
https://twitter.com/Zer0Security/status/983529439433777152

Copyright 2024, cxsecurity.com

 

Back to Top