漏洞描述 该漏洞源于Jira Server and DataCenter允许远程、未经身份验证的攻击者通过/secure/QueryComponent!Default中的一个信息泄露漏洞查看定制字段名和定制SLA名。
相关漏洞推荐 POC CVE-2017-9506: Atlassian Jira IconURIServlet - Cross-Site Scripting/Server-Side Request Forgery POC CVE-2018-20824: Atlassian Jira WallboardServlet <7.13.1 - Cross-Site Scripting POC CVE-2018-5230: Atlassian Jira Confluence - Cross-Site Scripting POC CVE-2019-11581: Atlassian Jira Server-Side Template Injection POC CVE-2019-3401: Atlassian Jira <7.13.3/8.0.0-8.1.1 - Incorrect Authorization POC CVE-2020-14179: Atlassian Jira Server/Data Center <8.5.8/8.6.0 - 8.11.1 - Information Disclosure POC CVE-2021-26086: Atlassian Jira Limited - Local File Inclusion POC CVE-2022-0540: Atlassian Jira Seraph - Authentication Bypass POC CVE-2019-11581: Atlassian Jira未授权服务端模板注入漏洞 POC CVE-2019-8442: Atlassian Jira webroot leak POC jira-setup: Atlassian JIRA Setup - Installer Atlassian Jira Mobile 插件 SSRF 漏洞 Atlassian Jira CVE-2022-0540认证绕过漏洞