Details
-
Type: Improvement
-
Status: Closed (View Workflow)
-
Priority: Major
-
Resolution: Done
-
Affects Version/s: None
-
Fix Version/s: None
-
Labels:None
-
Story Points:0.5
-
Epic Link:
-
Sprint:Fall 4 2021 Sep 27 - Oct 8
Description
See:
https://www.acunetix.com/vulnerabilities/web/atlassian-oauth-plugin-iconuriservlet-ssrf/
for possible vulnerability.
Propose course of action to mitigate risk.
This URL needs to be blocked:
https://jira.transvar.org/plugins/servlet/oauth/users/icon-uri?consumerUri=
Not sure if it will block functionality of the server, or what the normal function of this is.