Loading HuntDB...

GHSA-5rqp-fx48-4mvw

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability in the CSV importing feature of JSM Insight. When running in an environment like Amazon EC2, this flaw may be used to access to a metadata resource that provides access credentials and other potentially confidential information. The affected versions are before version 4.13.20, from version 4.14.0 before 4.20.8, and from version 4.21.0 before 4.22.2.

Related CVEs

Key Information

GHSA ID
GHSA-5rqp-fx48-4mvw
Published
July 27, 2022 12:00 AM
Last Modified
August 3, 2022 12:00 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 13, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.