CVE-2018-13404
Last modified
CVE-2018-13404 is a vulnerability of currently unknown severity. The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and from version 7.13.0 before version 7.13.1 allows remote attackers who have administrator rights to determine the existence of internal hosts & open ports and in some cases obtain service information from internal network resources via a Server Side Request Forgery (SSRF) vulnerability.. EPSS estimates a 1.14% chance of exploitation in the next 30 days.
Description
The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and from version 7.13.0 before version 7.13.1 allows remote attackers who have administrator rights to determine the existence of internal hosts & open ports and in some cases obtain service information from internal network resources via a Server Side Request Forgery (SSRF) vulnerability.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Jira | < 7.6.10 |
| Atlassian | Jira Server | >= 7.7.0, < 7.7.5 |
| Atlassian | Jira Server | >= 7.8.0, <= 7.8.4 |
| Atlassian | Jira Server | >= 7.9.0, <= 7.9.2 |
| Atlassian | Jira Server | >= 7.10.0, <= 7.10.2 |
| Atlassian | Jira Server | >= 7.11.0, < 7.11.3 |
| Atlassian | Jira Server | >= 7.12.0, < 7.12.3 |
| Atlassian | Jira Server | >= 7.13.0, < 7.13.1 |
References
- https://jira.atlassian.com/browse/JRASERVER-68527Vendor Advisory
- https://jira.atlassian.com/browse/JRASERVER-68527Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-13404?
How severe is CVE-2018-13404?
How do I fix CVE-2018-13404?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-13399The Microsoft Windows Installer for Atlassian Fisheye and Cr…
- CVE-2018-1340Prior to 1.0.0, Apache Guacamole used a cookie for client-si…
- CVE-2018-13400Several administrative resources in Atlassian Jira before ve…
- CVE-2018-13401The XsrfErrorAction resource in Atlassian Jira before versio…
- CVE-2018-13402Many resources in Atlassian Jira before version 7.6.9, from …
- CVE-2018-13403The two-dimensional filter statistics gadget in Atlassian Ji…
- CVE-2018-13405The inode_init_owner function in fs/inode.c in the Linux ker…7.8
- CVE-2018-13406An integer overflow in the uvesafb_setcmap function in drive…7.8
- CVE-2018-13407A CSRF issue was discovered in Jirafeau before 3.4.1. The "d…
- CVE-2018-13408An issue was discovered in Jirafeau before 3.4.1. The "searc…
- CVE-2018-13409An issue was discovered in Jirafeau before 3.4.1. The "searc…
- CVE-2018-13410Info-ZIP Zip 3.0, when the -T and -TT command-line options a…
Are you affected by CVE-2018-13404?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
