Mojira Archive
WEB-1032

SSRF in bugs.mojang.com

Hello! Just wanted to inform you that this JIRA is out of date and vulnerable to SSRF, specifically CVE-2017-9506 impacts you, allowing for requests to be made through your server. For instance,
https://bugs.mojang.com/plugins/servlet/oauth/users/icon-uri?consumerUri=http://bing.com
accesses bing. This vulnerability has been abused in the wild to bypass firewalls and proxy traffic. I strongly suggest patching your server and taking steps to keep your jira instance up to date.
Thanks!

Duplicate

Dylan

2018-05-10, 12:48 AM

2018-05-11, 04:44 PM

2018-05-10, 12:53 AM

0

2