{"id":"CVE-2019-8451","aliases":[],"url":"https://o3.security/vulnerability/CVE-2019-8451","summary":"The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network resources via a Server Side Request…","details":"The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.","published":"2019-09-11T14:15:12.430","modified":"2026-06-17T02:42:01.290","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"},"epss":{"score":0.94453,"percentile":0.99849,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":8,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"https://jira.atlassian.com/browse/JRASERVER-69793"},{"type":"ADVISORY","url":"https://jira.atlassian.com/browse/JRASERVER-69793"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T02:42:01.290"}}