#VU34185 Server-Side Request Forgery (SSRF) in Jira Software - CVE-2019-20408
Published: July 1, 2020 / Updated: August 8, 2020
Jira Software
Atlassian
Description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.