Later archive addition
Escalating SSRF in vulnerable Jira to RCE with Docker Engine API
A Jira SSRF is chained to an exposed, unauthenticated Docker Engine API. The server-side request reaches the local container daemon, creates an attacker-controlled container with host access, and turns a constrained web request primitive into remote command execution on the underlying system.
Record
- Researcher
- @username
- Published by
- Andmp | A blog about infosec, bug hunting and more!
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of @username, first published at the original source. Preserved copies are kept so the citation survives its host.