CyberRota Analysis
AI-GeneratedThe vulnerability affects the MCP server for Atlassian products, specifically in the JiraFetcher and ConfluenceFetcher sessions, where the lack of proper validation allows for server-side request forgery (SSRF) attacks. An attacker could exploit this flaw to redirect requests to internal addresses, potentially exposing sensitive information or compromising internal systems. Organizations using affected versions of Atlassian Confluence and Jira should prioritize upgrading to version 0.22.0 to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, _make_ssrf_safe_hook is omitted from JiraFetcher and ConfluenceFetcher sessions created through the basic-auth and oauth_pat branches. If an attacker-controlled or compromised configured Atlassian instance returns a redirect to an internal address, those sessions can follow the redirect without revalidating its destination. This issue is fixed in version 0.22.0.
Related CVEs
Other vulnerabilities affecting the same vendor(s)