{"id":1873,"date":"2018-05-30T17:00:31","date_gmt":"2018-05-30T17:00:31","guid":{"rendered":"http:\/\/82aafcae-d1a3-44dc-928e-7b1627700f62"},"modified":"2018-05-30T17:00:31","modified_gmt":"2018-05-30T17:00:31","slug":"jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\/","title":{"rendered":"Jira bug exposed private server keys at major companies, researcher finds"},"content":{"rendered":"<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet3.cbsistatic.com\/hub\/i\/r\/2018\/05\/30\/2bf08530-c0d0-47fb-8282-55c2af17f445\/resize\/770xauto\/62a36eeb34d5dbe2f4402bdc92b3bffe\/screen-shot-2018-05-18-at-2-54-58-pm.jpg\" class=\"\" alt=\"\" height=\"auto\" width=\"770\"\/><\/span><\/p>\n<p><span class=\"caption\">(Image: ZDNet)<\/span><\/p>\n<p>Several tech giants and major companies are exposing private server keys, thanks to a bug in widely used development software, which could allow a hacker to gain a foothold into their corporate networks.<\/p>\n<p>The bug, found in Atlassian software like Jira and Confluence, lets anyone easily obtain the secret access keys to the Amazon Web Services (AWS) instance that the software is hosted on.<\/p>\n<p>It&#8217;s because the software <a href=\"http:\/\/dontpanic.42.nl\/2017\/12\/there-is-proxy-in-your-atlassian.html?m=1\">contains a vulnerable proxy<\/a>, which can be abused to carry out cross-site scripting (XSS) attacks, and server-side request forgery (SSRF) attacks that return sensitive data from within the internal network.<\/p>\n<div class=\"relatedContent alignRight\">\n<h3 class=\"heading\"><span class=\"int\">what&#8217;s hot on zdnet<\/span><\/h3>\n<\/div>\n<p>An attacker can use an SSRF attack against the vulnerable proxy to siphon off AWS metadata such as secret access codes, as documented last year <a href=\"https:\/\/jira.atlassian.com\/browse\/BSERV-9649?page=com.atlassian.jira.plugin.system.issuetabpanels%3Aall-tabpanel\">in a bug report<\/a>.<\/p>\n<p>Those keys in the hands of an attacker could result in a takeover of the instance, leading to data theft or destruction.<\/p>\n<p>NIST <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-9506\">gave the bug<\/a> a 6.1 out of 10 severity rating on Atlassian products, all of which have since been fixed.<\/p>\n<p>Although most deployments have been updated, many companies are still running legacy versions of the software, often hosted on a company&#8217;s subdomain or are easily searchable. Security researcher <a href=\"https:\/\/twitter.com\/Random_Robbie\">Robert Wiggins<\/a> found over a dozen major companies running out-of-date and exposed Jira and Confluence deployments.<\/p>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_ZD_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\">\n<\/section>\n<p>Several companies &#8212; and one US government agency &#8212; have updated their deployments after we reached out.<\/p>\n<p>A spokesperson for EE, the largest cell network in the UK &#8212; which recently left <a href=\"https:\/\/www.zdnet.com\/article\/mobile-giant-left-code-system-online-default-password\/\">a critical code system online<\/a> &#8212; confirmed the company had fixed its vulnerable Jira deployment.<\/p>\n<p><a href=\"http:\/\/useinsider.com\/\">Insider<\/a>, a growth management platform, also fixed its Jira deployment after we reached out.<\/p>\n<p><a href=\"https:\/\/www.easymetrics.com\/\">Easy Metrics<\/a>, a cloud-based productivity software house, was running a vulnerable version of Jira. A spokesperson said the company &#8220;opted to shut down the instance and migrate our Jira workflow into the cloud,&#8221; and will notify any clients that may be affected.<\/p>\n<p>A division of the US Dept. of Health and Human Services, <a href=\"https:\/\/www.ahrq.gov\/\">the Agency for Healthcare Research and Quality<\/a>, pulled its vulnerable Jira server offline.<\/p>\n<p><a href=\"https:\/\/www.ieee.org\/\">IEEE<\/a>, a professional body for engineers, fixed its internal Jira deployment after we reached out.<\/p>\n<p>&#8220;Once we became aware of this matter, our team worked diligently to follow our security procedures,&#8221; a spokesperson said. &#8220;We have confirmed that the issue is resolved and no personal data had been exposed.&#8221;<\/p>\n<p><a href=\"https:\/\/ronin.cloud\/\">Ronin<\/a>, a cloud-based research software maker, secured its vulnerable Jira server, which the company&#8217;s chief executive Nathan Albrighton said was &#8220;isolated to our development environment,&#8221; but declined to comment further.<\/p>\n<p>And, <a href=\"http:\/\/www.aenetworks.com\/\">A&amp;E Networks<\/a>, a television and media giant, also left a vulnerable server exposed. The server was shut down, and the company declined to comment on the record.<\/p>\n<p>At least three companies &#8212; a musical instrument maker, a footwear retail giant, and a sports governing body &#8212; did not return several emails warning of the bugs, and remain vulnerable.<\/p>\n<p>For that reason, we&#8217;re not naming the affected companies.<\/p>\n<p>It&#8217;s thought that there are many other vulnerable deployments. Earlier this year, two Jira instances run by the US Dept. of Defense were fixed, according to <a href=\"https:\/\/medium.com\/bugbountywriteup\/piercing-the-veil-server-side-request-forgery-to-niprnet-access-c358fd5e249a\">one bug bounty write-up<\/a>.<\/p>\n<p>For now, updating your Atlassian software sounds like the best solution.<\/p>\n<div class=\"relatedContent alignNone\" readability=\"7.7336683417085\">\n<p class=\"title\"><a href=\"https:\/\/medium.com\/@zackwhittaker\/how-to-contact-me-securely-38dc5c5bc756\" data-omniture-track=\"moduleClick\" data-omniture-track-data=\"{&quot;moduleInfo&quot;: &quot;pinbox&quot;, &quot;pageType&quot;: &quot;article&quot;}\">Contact me securely<\/a><\/p>\n<p class=\"dek\">Zack Whittaker can be reached securely on Signal and WhatsApp at 646-755\u20138849, and his PGP fingerprint for email is: 4D0E 92F2 E36A EC51 DAAE 5D97 CB8C 15FA EB6C EEA5.<\/p>\n<p class=\"read-more\"><a href=\"https:\/\/medium.com\/@zackwhittaker\/how-to-contact-me-securely-38dc5c5bc756\" data-omniture-track=\"moduleClick\" data-omniture-track-data=\"{&quot;moduleInfo&quot;: &quot;pinbox&quot;, &quot;pageType&quot;: &quot;article&quot;}\">Read More<\/a><\/p>\n<\/div>\n<div class=\"relatedContent alignNone\">\n<h3 class=\"heading\"><span class=\"int\">ZDNET INVESTIGATIONS<\/span><\/h3>\n<\/div>\n<p>READ MORE <a href=\"https:\/\/www.zdnet.com\/article\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\/#ftag=RSSbaffb68\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A major TV network, a UK cell giant, and one US government agency are among the companies affected.<br \/>\nREAD MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":1874,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-1873","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Jira bug exposed private server keys at major companies, researcher finds 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Jira bug exposed private server keys at major companies, researcher finds 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2018-05-30T17:00:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"770\" \/>\n\t<meta property=\"og:image:height\" content=\"440\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Jira bug exposed private server keys at major companies, researcher finds\",\"datePublished\":\"2018-05-30T17:00:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\\\/\"},\"wordCount\":595,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds.jpg\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\\\/\",\"name\":\"Jira bug exposed private server keys at major companies, researcher finds 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds.jpg\",\"datePublished\":\"2018-05-30T17:00:31+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds.jpg\",\"width\":770,\"height\":440},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Jira bug exposed private server keys at major companies, researcher finds\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Jira bug exposed private server keys at major companies, researcher finds 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\/","og_locale":"en_US","og_type":"article","og_title":"Jira bug exposed private server keys at major companies, researcher finds 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2018-05-30T17:00:31+00:00","og_image":[{"width":770,"height":440,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Jira bug exposed private server keys at major companies, researcher finds","datePublished":"2018-05-30T17:00:31+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\/"},"wordCount":595,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds.jpg","articleSection":["ZDNet | Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\/","url":"https:\/\/www.threatshub.org\/blog\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\/","name":"Jira bug exposed private server keys at major companies, researcher finds 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds.jpg","datePublished":"2018-05-30T17:00:31+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds.jpg","width":770,"height":440},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/jira-bug-exposed-private-server-keys-at-major-companies-researcher-finds\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Jira bug exposed private server keys at major companies, researcher finds"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/1873","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=1873"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/1873\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/1874"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=1873"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=1873"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=1873"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}