outdated-software

1 article
sort: new top best
clear filter
0 5/10

Researcher discovered an SSRF vulnerability in an outdated Jira instance that allowed Server-Side Request Forgery via the oauth/users/icon-uri endpoint, which was then chained to deliver XSS payloads by hosting malicious HTML and bypassing firewall protections. The vulnerability affected multiple high-profile organizations including European Commission, Motorola Solution, and several universities.

Adesh Kolte Jira European Commission Motorola Solution Mass.gov Cambridge University Press Stanford University Google
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details