CyberRota Analysis
AI-GeneratedThe vulnerability affects the MCP Atlassian server used with Confluence and Jira, specifically in versions prior to 0.22.0, where improper URL validation can lead to server-side request forgery (SSRF). This flaw allows an attacker to craft a URL that appears valid, enabling unauthorized access to internal network resources while bypassing security measures. Organizations utilizing affected versions should prioritize patching to version 0.22.0 to mitigate the risk of potential data exposure and internal network compromise.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_url_for_ssrf has a backslash authority confusion because it interprets the authority differently from the Requests connection layer in the header-based Jira and Confluence URL authentication flow. A crafted URL can validate as an external hostname while the HTTP client connects to an internal host, permitting server-side requests to protected network resources. This issue is fixed in version 0.22.0.
Related CVEs
Other vulnerabilities affecting the same vendor(s)