Description
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.
Remediation
References
Related Vulnerabilities
TYPO3 Other Vulnerability (CVE-2012-1605)
WordPress Plugin Easy Event calendar Cross-Site Scripting (1.0)
WordPress Plugin Magic Post Voice Cross-Site Scripting (1.2)
PHP Other Vulnerability (CVE-2015-4603)
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-0701)