Junglewise Threat Intelligence

CVE-2025-45939: Apwide Golive SSRF in test webhook function

CVE-2025-45939 · Severity: medium · CVSS 6.5 · Published 2025-07-25

Executive brief

Apwide Golive, a Jira plugin used for managing release and test environments, contains a security flaw in its webhook testing feature. An attacker could exploit this to make the Jira server send unauthorized requests to internal or external systems. This could lead to the exposure of internal network information or unauthorized access to internal services that are not intended to be reachable from the outside.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the Apwide Golive plugin for Jira (specifically version 10.2.0) within the test webhook functionality. The vulnerability stems from insufficient validation of user-supplied URLs in the automation engine, allowing a user with Golive Administrator permissions to trigger requests from the Jira server to arbitrary destinations. While the attack requires high complexity or specific permissions, it can bypass network boundaries to reach internal metadata services or other internal network resources. The vendor has addressed this in version 10.5.2 (and 9.31.4) by enforcing Jira's native outgoing URL allowlist for automation rule endpoints.

Affected products

  • Apwide Golive 10.2.0

Timeline

  • 2025-06-06: patched: Fixed in versions 10.5.2 and 9.31.4
  • 2025-07-25: advisory: NVD publication date

References