Sceawere
Vulnerability Detail
CVE-2026-100900UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SSRF in DevaslanPHP Jira Import
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 5h ago
- Vendor
- DevaslanPHP
- Product
- project-management
- Attack Type
- Server-Side Request Forgery
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability has been found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0-beta1. Affected is the function updateJiraProjects of the file /jira-import of the component Jira Import. The manipulation of the argument host/username/token leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-09-28T03:16:38.630Z",
"pubdate": "2026-09-28T03:16:38.630Z",
"executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Jira Import component of DevaslanPHP project-management versions 1.2.1 through v2.0.0-beta1.\nThe vulnerability resides within the updateJiraProjects function located in the /jira-import file.\nBy manipulating the host, username, or token parameters, an unauthenticated remote attacker can force the application server to perform unauthorized HTTP requests to arbitrary targets.\nThe risk implication is significant as it allows attackers to bypass network perimeter defenses, interact with internal services unreachable from the public internet, or perform reconnaissance on the local network infrastructure.\nThe vulnerability is currently publicly disclosed, and given the lack of vendor response, organizations should assume an active exploitation risk exists for any exposed instance of the software.\nExploitation requires no specialized authentication, enabling remote actors to leverage the application as a proxy for malicious network activity.",
"technicalDetails": "The vulnerability is classified as a Server-Side Request Forgery (SSRF) occurring due to insufficient input validation and sanitization of user-supplied parameters within the updateJiraProjects function of the /jira-import component.\nIn the affected versions (1.2.1, 1.2.2, 1.2.3, 1.2.4, and v2.0.0-beta1), the application fails to restrict the 'host', 'username', and 'token' arguments provided to the Jira integration interface.\nWhen these parameters are submitted via an HTTP request, the underlying server-side logic utilizes these inputs to construct outbound requests to external Jira instances without verifying that the destination address adheres to a strict allowlist or is an expected internal/external endpoint.\nThe attack flow proceeds as follows: An attacker sends a crafted POST request to the /jira-import endpoint. The attacker populates the 'host' parameter with a URI pointing to a target internal service (e.g., http://127.0.0.1:6379 or a protected internal management API). Because the application logic does not validate the host header or the URL structure, the server initiates a GET or POST request to the attacker-defined target.\nBy controlling these arguments, the attacker can influence the destination of the request, potentially bypassing firewalls, accessing metadata services (such as AWS Instance Metadata Service), or interacting with internal non-public microservices.\nBecause the server originates the request, the response may contain sensitive information from the internal target, which might be reflected back to the attacker or lead to actionable state changes within the internal network.\nThe absence of robust server-side request validation allows the exploitation of this vulnerability remotely without the need for prior authentication. This effectively turns the DevaslanPHP project-management instance into an open proxy for the internal network environment.\nSuccessful exploitation facilitates post-exploitation activities such as port scanning of the internal infrastructure, cloud credential theft, or the execution of unauthorized actions against internal APIs that rely on implicit trust based on network location."
}