PT-2018-6353 · Atlassian+1 · Trello+2
Published
2018-01-17
·
Updated
2018-02-02
·
CVE-2017-16865
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Atlassian Jira versions prior to 7.6.1
Description:
The issue allows remote attackers to access internal network resources via a Server Side Request Forgery (SSRF) in the Trello importer. This flaw can be used to access a metadata resource that provides access credentials and other potentially confidential information, especially in environments like Amazon EC2.
Recommendations:
For versions prior to 7.6.1, update to version 7.6.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Trello importer to minimize the risk of exploitation.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amazon Ec2
Jira
Trello