Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-16865

Опубликовано: 17 янв. 2018
Источник: nvd
CVSS3: 5.3
CVSS2: 3.5
EPSS Низкий

Описание

The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF). When running in an environment like Amazon EC2, this flaw maybe used to access to a metadata resource that provides access credentials and other potentially confidential information.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:atlassian:jira:*:*:*:*:*:*:*:*
Версия до 7.6.1 (исключая)

EPSS

Процентиль: 36%
0.00145
Низкий

5.3 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 5.3
github
около 3 лет назад

The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF). When running in an environment like Amazon EC2, this flaw maybe used to access to a metadata resource that provides access credentials and other potentially confidential information.

EPSS

Процентиль: 36%
0.00145
Низкий

5.3 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-918