Web Hack List

Later archive addition

Escalating SSRF in vulnerable Jira to RCE with Docker Engine API

A Jira SSRF is chained to an exposed, unauthenticated Docker Engine API. The server-side request reaches the local container daemon, creates an attacker-controlled container with host access, and turns a constrained web request primitive into remote command execution on the underlying system.

Record

Researcher
@username
Published by
Andmp | A blog about infosec, bug hunting and more!

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @username, first published at the original source. Preserved copies are kept so the citation survives its host.