The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and from version 7.13.0 before version 7.13.1 allows remote attackers who have administrator rights to determine the existence of internal hosts & open ports and in some cases obtain service information from internal network resources via a Server Side Request Forgery (SSRF) vulnerability.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: atlassian

Published: 2019-01-18T00:00:00

Updated: 2019-02-13T17:57:01

Reserved: 2018-07-06T00:00:00


Link: CVE-2018-13404

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-02-13T18:29:00.417

Modified: 2022-03-25T17:22:38.787


Link: CVE-2018-13404

JSON object: View

cve-icon Redhat Information

No data.

CWE