S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2017-9506 Scanner

CVE-2017-9506 scanner - Server-Side-Request-Forgery (SSRF) vulnerability in Atlassian OAuth Plugin

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-9506
6.1
CVSS

The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server Side Request Forgery (SSRF).

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Atlassian OAuth Pluginby Atlassian
From version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4.
Updated Aug 5, 2026View on NVD →
Detail

The Atlassian OAuth Plugin is a software component used for authentication by Atlassian's suite of software tools, including JIRA, Confluence, and Bitbucket. The plugin, which is included in these software products, allows users to log in and access secure resources without having to enter their username and password each time. This greatly increases the security of sensitive information and is a key component of Atlassian's security strategy.

One vulnerability that has been detected in the Atlassian OAuth Plugin is CVE-2017-9506. This vulnerability allows remote attackers to access internal network resources and perform an XSS attack via Server-Side Request Forgery (SSRF). This means that an attacker can remotely access and manipulate internal resources on the network, as well as execute malicious code, bypassing the security measures put in place by Atlassian.

If exploited, this vulnerability can lead to a range of serious consequences, including the loss of sensitive information, unauthorized access to systems and data, and damage to the reputation of the affected organization. The possibility of an attacker gaining access to internal network resources without authorization is a major security threat and could cause significant harm.

In conclusion, the Atlassian OAuth Plugin is a critical component of Atlassian's suite of software tools. However, a recently discovered vulnerability in the plugin highlights the importance of taking proactive security measures to protect against potential threats. s4e.io provides pro features that allow users to stay informed about vulnerabilities in their digital assets, enabling them to take quick and effective action to protect their sensitive information and ensure the safety of their systems and networks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users of the Atlassian OAuth Plugin can take the following precautions:

  • Upgrade to the latest version of the product, including version 1.9.12 or 2.0.4 or later.
  • Set up a firewall to block incoming requests from untrusted sources.
  • Deploy web application firewalls that filter incoming and outgoing traffic to detect and block malicious requests.
  • Train users and administrators on how to identify and report potential security threats.
  • Regularly perform security audits and vulnerability scans to identify and address potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-9506 scanner - Server-Side-Request-Forgery (SSRF) vulnerability in Atlassian OAuth Plugin | S4E