312
VMScore

CVE-2017-16865

Published: 17/01/2018 Updated: 02/02/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.3 | Impact Score: 3.6 | Exploitability Score: 1.6
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N

Vulnerability Summary

The Trello importer in Atlassian Jira before version 7.6.1 allows remote malicious users to access the content of internal network resources via a Server Side Request Forgery (SSRF). When running in an environment like Amazon EC2, this flaw maybe used to access to a metadata resource that provides access credentials and other potentially confidential information.

Vulnerable Product Search on Vulmon Subscribe to Product

atlassian jira