Executive brief
FireFighter, an incident management tool, contains a security flaw in its Jira integration component. An unauthenticated attacker can exploit this to force the application to make requests to internal systems, potentially stealing sensitive AWS cloud credentials. This could lead to a full compromise of the cloud environment where the application is hosted.
Technical details
The `POST /api/v2/firefighter/raid/jira_bot` endpoint in the `firefighter-incident` package fails to enforce authentication despite documentation suggesting otherwise. The `attachments` parameter is processed by `httpx.get()` without URL validation or destination filtering. An unauthenticated remote attacker can provide a URL pointing to the AWS Instance Metadata Service (IMDSv1) at `169.254.169.254`. The application fetches the metadata and uploads it as an attachment to a Jira ticket, effectively exfiltrating temporary IAM credentials. This is fixed in version 0.0.54 by enforcing `IsAuthenticated` permissions and implementing strict URL validation that rejects private, loopback, and link-local IP ranges.
Affected products
- ManoManoTech firefighter-incident < 0.0.54
Timeline
- 2026-04-24: patched: Fix committed to repository
- 2026-05-05: disclosed: GitHub Advisory published
- 2026-05-11: advisory: NVD published CVE-2026-42864