
Script Python per sfruttare CVE-2019-3403 per estrarre informazioni utente da istanze JIRA vulnerabili tramite l'API di ricerca utente non autenticata.
Volevo poter sfruttare facilmente CVE-2019-3403 per raccogliere tutti gli utenti da un'applicazione JIRA, quindi ho messo insieme questo script. Non è il codice più pulito in assoluto e non gestisce richieste che restituiscono oltre 1000 utenti (li troncherà semplicemente ai primi 1000), ma può rapidamente raccogliere tutti gli utenti da un server JIRA vulnerabile.
usage: scrape_jira.py [-h] -d DOMAIN [-q QUERY] [-o OUT] [-v]
Scrape User Information from Vulnerable JIRA Instances [CVE-2019-3403]
optional arguments:
-h, --help show this help message and exit
-d DOMAIN, --domain DOMAIN
The domain of the target
-q QUERY, --query QUERY
Specific query to run against the API
-o OUT, --out OUT Output to a file
-v, --verbose Verbose output
Scrape everything and save output to a file:
python3 CVE-2019-3403.py -d jira.example.com -o out.txt -v
Just look for a specific user:
python3 CVE-2019-3403.py -d jira.example.com -q admin