Impact
The MCP‑Atlassian server validates the X‑Atlassian‑Jira‑Url and X‑Atlassian‑Confluence‑Url headers only once at middleware time; the outbound request is constructed with the raw hostname and resolved again at connection time without IP pinning. An attacker can perform DNS‑rebinding so that the first resolution points to a public IP, while the second resolution points to an internal IP such as the cloud metadata service 169.254.169.254 or other private addresses. This allows an unauthenticated server‑side request to sensitive internal or cloud metadata resources, exposing confidential data. The vulnerability is identified as a Server‑Side Request Forgery (CWE‑918).
Affected Systems
The affected product is the MCP‑Atlassian server for Atlassian Confluence and Jira, distributed by Sooperset. Versions from 0.17.0 until (but not including) 0.22 in release 0.22.0; any deployment of an earlier version is impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates medium the vulnerability is not listed in the KEV catalog. Despite the medium CVSS score, the EPSS score of <1% indicates a very low probability of exploitation. The flaw allows an attacker who can reach the MCP‑Atlassian server to cause the server to resolve a DNS‑rebinding name differently at validation and at connection time, enabling unauthenticated server‑side requests to internal addresses such as 169.254.169.254. While no official exploitation statistics are publicly reported, the lack of authentication combined with the potential to access internal services suggests a moderate exploitation risk. Attackers would need network access to the MCP server, but no additional privileges are required.
OpenCVE Enrichment