我想能够轻松利用CVE-2019-3403从JIRA应用中抓取所有用户,于是随手写了这个脚本。它并非最整洁的代码,也无法处理返回超过1000个用户的请求(只会截取前1000个)——但可以快速从有漏洞的JIRA服务器抓取所有用户。
usage: scrape_jira.py [-h] -d DOMAIN [-q QUERY] [-o OUT] [-v]
Scrape User Information from Vulnerable JIRA Instances [CVE-2019-3403]
optional arguments:
-h, --help show this help message and exit
-d DOMAIN, --domain DOMAIN
The domain of the target
-q QUERY, --query QUERY
Specific query to run against the API
-o OUT, --out OUT Output to a file
-v, --verbose Verbose output
抓取所有信息并保存到文件:
python3 CVE-2019-3403.py -d jira.example.com -o out.txt -v
仅查找特定用户:
python3 CVE-2019-3403.py -d jira.example.com -q admin