PT-2022-5982 · Amazon+1 · Amazon Ec2+2
Published
2022-06-26
·
Updated
2022-08-02
·
CVE-2021-43959
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Atlassian Jira Service Management Server and Data Center versions prior to 4.13.20
Atlassian Jira Service Management Server and Data Center versions 4.14.0 through 4.20.8
Atlassian Jira Service Management Server and Data Center versions 4.21.0 through 4.22.2
Description
The vulnerability is related to insufficient server-side request checking in the CSV import feature of JSM Insight, allowing a remote attacker to perform a Server-Side Request Forgery (SSRF) attack. This flaw can be used to access internal network resources, including metadata resources that provide access credentials and other potentially confidential information, especially in environments like Amazon EC2.
Recommendations
For versions prior to 4.13.20, update to version 4.13.20 or later.
For versions 4.14.0 through 4.20.8, update to version 4.20.8 or later.
For versions 4.21.0 through 4.22.2, update to version 4.22.2 or later.
As a temporary workaround, consider restricting access to the CSV importing feature of JSM Insight until a patch is applied.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amazon Ec2
Jsm Insight
Jira Service Management Server