Description
The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF). When running in an environment like Amazon EC2, this flaw maybe used to access to a metadata resource that provides access credentials and other potentially confidential information.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-8039 | The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF). When running in an environment like Amazon EC2, this flaw maybe used to access to a metadata resource that provides access credentials and other potentially confidential information. |
References
| Link | Providers |
|---|---|
| https://jira.atlassian.com/browse/JRASERVER-66642 |
|
History
No history.
Status: PUBLISHED
Assigner: atlassian
Published:
Updated: 2024-09-17T01:30:44.872Z
Reserved: 2017-11-16T00:00:00.000Z
Link: CVE-2017-16865
No data.
Status : Modified
Published: 2018-01-17T14:29:00.217
Modified: 2024-11-21T03:17:07.717
Link: CVE-2017-16865
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD