近日,我司应急团队监测到Atlassian 发布安全公告,修复了一个Atlassian Jira 多款产品Mobile Plugin中的服务端请求伪造漏洞(SSRF)。经过身份验证的远程攻击者可通过向Jira Core REST API发送特制请求,从而伪造服务端发起请求,从而导致敏感信息泄露,同时为下一步攻击利用提供条件。需注意的是,若服务端开启注册功能,则未授权用户可通过注册获取权限进而利用。
【受影响版本】
8.0 <= Jira Core Server/Jira Software Server/Jira Software Data Center < 8.13.22
Jira Core Server/Jira Software Server/Jira Software Data Center 8.14.x
Jira Core Server/Jira Software Server/Jira Software Data Center 8.15.x
Jira Core Server/Jira Software Server/Jira Software Data Center 8.16.x
Jira Core Server/Jira Software Server/Jira Software Data Center 8.17.x
Jira Core Server/Jira Software Server/Jira Software Data Center 8.18.x
Jira Core Server/Jira Software Server/Jira Software Data Center 8.19.x
8.20 <= Jira Core Server/Jira Software Server/Jira Software Data Center < 8.20.10
Jira Core Server/Jira Software Server/Jira Software Data Center 8.21.x
8.22.0 <= Jira Core Server/Jira Software Server/Jira Software Data Center < 8.22.4
4.0 <= Jira Service Management Server/Data Center < 4.13.22
Jira Service Management Server/Data Center 4.14.x
Jira Service Management Server/Data Center 4.15.x
Jira Service Management Server/Data Center 4.16.x
Jira Service Management Server/Data Center 4.17.x
Jira Service Management Server/Data Center 4.18.x
Jira Service Management Server/Data Center 4.19.x
4.20.0 <= Jira Service Management Server/Data Center < 4.20.10
Jira Service Management Server/Data Center 4.21.x
4.22.0 <= Jira Service Management Server/Data Center < 4.22.4
【安全版本】
Jira Core Server/Jira Software Server/Jira Software Data Center 8.13.x >= 8.13.22
Jira Core Server/Jira Software Server/Jira Software Data Center 8.20.x >= 8.20.10
Jira Core Server/Jira Software Server/Jira Software Data Center 8.22.x >= 8.22.4
Jira Core Server/Jira Software Server/Jira Software Data Center >= 9.0.0
Jira Service Management Server/Data Center4.13.x >= 4.13.22
Jira Service Management Server/Data Center4.20.x >= 4.20.10
Jira Service Management Server/Data Center4.22.x >= 4.22.4
Jira Service Management Server/Data Center >= 5.0.0
Atlassian Jira是澳大利亚Atlassian公司的一套缺陷跟踪管理系统。该系统主要用于对工作中各类问题、缺陷进行跟踪管理。