HTTP: Atlassian OAuth plugin Server Side Request Forgery

This signature detects attempts to exploit a known vulnerability against Atlassian. A successful attack can lead to XSS attack via server side request forgery.

Extended Description

The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server Side Request Forgery (SSRF).

Affected Products

Atlassian oauth

Short Name
HTTP:CTS:ATLASSIAN-OAUTH-SSRF
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
Atlassian CVE-2017-9506 Forgery OAuth Request Server Side plugin
Release Date
03/17/2020
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Atlassian

CVSS Score

4.3

Found a potential security threat?