PT-2026-96902 · Unknown · Mcp-Attlasian
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MCP Atlassian versions prior to 0.22.0
Description
An unauthenticated caller can perform a Server-Side Request Forgery (SSRF) attack using a DNS-rebinding technique. The software employs a validate-then-use pattern where the
validate url for ssrf() function resolves a hostname to ensure it is globally routable, but the actual HTTP connection occurs later with a separate DNS resolution. An attacker can provide a hostname that returns a public address during validation and an internal address during the actual connection, allowing requests to reach internal services or cloud metadata services (e.g., 169.254.169.254) to steal IAM credentials or scan internal networks.This issue is triggered via the following header-supplied parameters:
X-Atlassian-Jira-UrlX-Atlassian-Confluence-Url
Recommendations
Update to version 0.22.0.
As a temporary mitigation, restrict the use of header-based Personal Access Token (PAT) authentication if not strictly required.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcp-Attlasian