ZeroHour

CVE-2017-9506

PoC ×3
CVSS 3.0
6.1 medium
EPSS
72%p99
Published
()
Modified
Description

The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server Side Request Forgery (SSRF).

Vendors
atlassian
Products
oauth
Weakness
CWE-918
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news