Atlassian Jira before 8.4.0 contains a server-side request forgery vulnerability in its gadget request functionality. A logic error in the JiraWhitelist class permits a remote attacker to cause Jira to retrieve content from internal network resources that should be blocked by URL-whitelisting controls.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Bash script (CVE-2019-8451.sh) that serves as a proof-of-concept exploit for CVE-2019-8451, a Server-Side Request Forgery (SSRF) vulnerability in Atlassian products (such as Jira or Confluence). The script takes two arguments: the base URL of the target Atlassian instance and the URL to which the SSRF should be directed. It crafts a request to the /plugins/servlet/gadgets/makeRequest endpoint, exploiting the vulnerability to force the server to make a request to an attacker-controlled or internal URL. The script analyzes the response for signs of successful SSRF, such as the presence of session cookies or the X-AUSERNAME header, and displays the raw response for further inspection. The exploit is a standalone Bash script, requires no dependencies beyond curl, and is intended for testing or demonstration purposes.
This repository contains a Python proof-of-concept exploit for CVE-2019-8451, a Server Side Request Forgery (SSRF) vulnerability in Atlassian Jira (prior to version 8.4.0). The exploit script (CVE-2019-8451.py) allows an attacker to interactively supply a target Jira URL and an arbitrary SSRF target URL. It crafts a request to the vulnerable endpoint '/plugins/servlet/gadgets/makeRequest' with a manipulated 'url' parameter, causing the Jira server to make a request to the attacker-supplied SSRF target. The script checks for a successful response and prints out relevant headers and content, demonstrating the ability to access internal or external resources from the Jira server's perspective. The README.md provides usage instructions, example output, and background on the vulnerability. No payload is delivered beyond the SSRF request itself, and the exploit is a standalone Python script requiring only the 'requests' library.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.