Uploaded image for project: 'Xray for Jira'
  1. Xray for Jira
  2. XRAY-7391

Dependency "client-core" can cause server-side request forgery on Xray integrations

    XporterXMLWordPrintable

Details

    • UNCOVERED

    Description

      Xray integrations that are using client-core dependency can be vulnerable to server-side request forgery. We are trusting the client to provide a url of a Jira instance, but in fact the user can provide another url to perform a request to a private service in the network that is running Bamboo, Jenkins or TeamCity.

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              prpa Paulo Alves
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - 0 minutes
                  0m
                  Remaining:
                  Remaining Estimate - 0 minutes
                  0m
                  Logged:
                  Time Spent - 1 day, 4 hours, 20 minutes
                  1d 4h 20m