From e321f23dcd24379b0c68dc809475c7303ea8fdda Mon Sep 17 00:00:00 2001 From: Micha3lb3n Date: Wed, 8 Jul 2020 20:46:44 +0530 Subject: [PATCH 1/2] Adding jira misconfig workflow --- workflows/jira-misconfiguration-workflow.yaml | 23 +++++++++++++++++++ 1 file changed, 23 insertions(+) create mode 100644 workflows/jira-misconfiguration-workflow.yaml diff --git a/workflows/jira-misconfiguration-workflow.yaml b/workflows/jira-misconfiguration-workflow.yaml new file mode 100644 index 0000000000..b7ff5bb5cc --- /dev/null +++ b/workflows/jira-misconfiguration-workflow.yaml @@ -0,0 +1,23 @@ +id: jira-misconfiguration-workflow + +info: + name: Jira misconfiguration workflow + author: micha3lb3n + +variables: + jira_detect: technologies/jira-detect.yaml + jira_signup: security-misconfiguration/jira-service-desk-signup.yaml + jira_projects: security-misconfiguration/jira-unauthenticated-projects.yaml + jira_dashboard: security-misconfiguration/jira-unauthenticated-dashboards.yaml + jira_filters: security-misconfiguration/jira-unauthenticated-popular-filters.yaml + jira_user_picker: security-misconfiguration/jira-unauthenticated-user-picker.yaml + +logic: + | + if jira_detect(){ + jira_signup() + jira_projects() + jira_dashboard() + jira_filters() + jira_user_picker() + } From 45b992c764dc28fe5be01f6145c7da9ee7c3f0bb Mon Sep 17 00:00:00 2001 From: bauthard <8293321+bauthard@users.noreply.github.com> Date: Wed, 8 Jul 2020 23:00:21 +0530 Subject: [PATCH 2/2] Update jira-misconfiguration-workflow.yaml --- workflows/jira-misconfiguration-workflow.yaml | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/workflows/jira-misconfiguration-workflow.yaml b/workflows/jira-misconfiguration-workflow.yaml index b7ff5bb5cc..190794410d 100644 --- a/workflows/jira-misconfiguration-workflow.yaml +++ b/workflows/jira-misconfiguration-workflow.yaml @@ -1,7 +1,7 @@ -id: jira-misconfiguration-workflow +id: jira-exploitaiton-workflow info: - name: Jira misconfiguration workflow + name: Jira Exploitaiton workflow author: micha3lb3n variables: @@ -11,6 +11,11 @@ variables: jira_dashboard: security-misconfiguration/jira-unauthenticated-dashboards.yaml jira_filters: security-misconfiguration/jira-unauthenticated-popular-filters.yaml jira_user_picker: security-misconfiguration/jira-unauthenticated-user-picker.yaml + jira_cve_1: cves/CVE-2019-8449.yaml + jira_cve_2: cves/CVE-2019-8451.yaml + jira_cve_3: cves/CVE-2017-9506.yaml + jira_cve_4: cves/CVE-2018-20824.yaml + logic: | @@ -20,4 +25,8 @@ logic: jira_dashboard() jira_filters() jira_user_picker() + jira_cve_1() + jira_cve_2() + jira_cve_3() + jira_cve_4() }