CVE-2018-13404Server-Side Request Forgery in Atlassian Jira

Severity
4.1MEDIUMNVD
EPSS
0.1%
top 65.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 13
Latest updateMay 13

Description

The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and from version 7.13.0 before version 7.13.1 allows remote attackers who have administrator rights to determine the existence of internal hosts & open ports and in som

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:NExploitability: 2.3 | Impact: 1.4

Affected Packages3 packages

NVDatlassian/jira_server7.7.07.7.5+6
CVEListV5atlassian/jiraunspecified7.6.10+14
NVDatlassian/jira< 7.6.10

🔴Vulnerability Details

2
GHSA
GHSA-5pg5-2rp3-4hw8: The VerifyPopServerConnection resource in Atlassian Jira before version 72022-05-13
CVEList
CVE-2018-13404: The VerifyPopServerConnection resource in Atlassian Jira before version 72019-02-13
CVE-2018-13404 — Server-Side Request Forgery | cvebase