S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-8451 Scanner

CVE-2019-8451 scanner - Server-Side Request Forgery (SSRF) vulnerability in Atlassian Jira

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
4.6k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-8451
6.5
CVSS

The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Jiraby Atlassian
AFFECTED< 8.4.0SAFE ✓≥ 8.4.0
Updated Aug 21, 2026View on NVD →
Detail

Atlassian Jira is a popular software used for project management, issue tracking, and bug tracking. It is commonly used by software development teams, but can also be used by other teams for project management purposes. The platform allows for collaboration, visibility, and organization of tasks.

One of the vulnerabilities detected in Atlassian Jira is CVE-2019-8451. It is a Server Side Request Forgery (SSRF) vulnerability that allows remote attackers to access the content of internal network resources through the /plugins/servlet/gadgets/makeRequest resource. This vulnerability is due to a logic bug in the JiraWhitelist class.

If exploited, the CVE-2019-8451 vulnerability can lead to unauthorized access to sensitive data stored in the internal network resources. Attackers can use this vulnerability to gain access to users’ credentials, personal information, or any confidential data stored in the vulnerable system. In addition, attackers can also use this vulnerability to perform various malicious activities, including stealing data, injecting malware, or even taking over the vulnerable system.

Thanks to the Pro features of the s4e.io platform, reading this article gives readers the opportunity to learn about vulnerabilities that may be present in their digital assets. By utilizing the features offered by s4e.io, individuals can quickly and easily identify any vulnerabilities in their systems and take the necessary precautions to protect against potential attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several precautions that can be taken, including:

  • Regularly applying software updates and patches to the Jira system.
  • Configuring firewalls and other security measures to prevent unauthorized access to the Jira system.
  • Implementing two-factor authentication and other user authentication mechanisms to protect against unauthorized access to user accounts.
  • Regularly monitoring the system for suspicious activities and taking immediate action if any are detected.
  • Ensuring that access controls and other security measures are properly configured and enforced.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.