<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Jira Server (&lt; 8.4.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/jira-server--8.4.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 07:52:08 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/jira-server--8.4.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Atlassian Jira Server SSRF Vulnerability (CVE-2019-8451)</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2019-8451/</link><pubDate>Mon, 28 Sep 2026 07:52:08 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2019-8451/</guid><description>CVE-2019-8451 is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the Atlassian Jira Server gadgets servlet that allows attackers to access internal network resources.</description><content:encoded><![CDATA[<p>CVE-2019-8451 is a Server-Side Request Forgery (SSRF) vulnerability affecting Atlassian Jira Server versions prior to 8.4.0. The vulnerability exists within the /plugins/servlet/gadgets/makeRequest endpoint, which fails to correctly validate the target URL provided in the request parameter. A logic error within the JiraWhitelist class allows an unauthenticated remote attacker to bypass intended security controls and force the Jira server to initiate HTTP requests to arbitrary internal or external network resources. This flaw can be weaponized to conduct reconnaissance of internal services, interact with private APIs, or exfiltrate sensitive data reachable from the Jira server's network segment. The public availability of functional exploit code increases the risk of exploitation for organizations that have not yet upgraded their Jira instances to the patched version, 8.4.0 or later.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The attacker performs network reconnaissance to identify internet-facing Jira Server instances.</li>
<li>The attacker sends a crafted HTTP GET or POST request to the target's /plugins/servlet/gadgets/makeRequest endpoint.</li>
<li>The attacker injects a target URL into the 'url' query parameter of the request.</li>
<li>The Jira Server's gadgets servlet processes the request and passes the URL to the flawed JiraWhitelist class for validation.</li>
<li>Due to the logic bug, the validator fails to identify or block the malicious URL destination.</li>
<li>The Jira Server executes an outbound request to the attacker-supplied URL on behalf of the server.</li>
<li>The server receives the response from the internal resource and returns the content of that resource to the attacker in the HTTP response body.</li>
<li>The attacker parses the response to discover internal network infrastructure or exfiltrate sensitive internal service data.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to bypass network perimeter security, conduct internal network discovery, and access sensitive data hosted on internal services that are not directly exposed to the internet. While the vulnerability does not directly grant Remote Code Execution (RCE) on the Jira host, it provides a powerful primitive for lateral movement and further exploitation of the internal environment.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Upgrade all instances of Atlassian Jira Server to version 8.4.0 or later to remediate the logic flaw in JiraWhitelist.</li>
<li>Deploy detection rules to monitor for suspicious requests to the gadgets servlet as outlined below.</li>
<li>Review web server access logs for anomalous traffic targeting the /plugins/servlet/gadgets/makeRequest path, especially those with outbound-looking URLs in the query string.</li>
<li>Implement egress filtering on the host running Jira to restrict the server from initiating unauthorized connections to sensitive internal subnets.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>vulnerability</category><category>ssrf</category><category>atlassian</category><category>jira</category></item></channel></rss>