← Back

CVE-2020-36232

nvd nist
Published: Feb 22, 2021Modified: Nov 21, 2024

JSON object

Loading...
5.0
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Exploitability: 3.1 / Impact: 1.4
Source: NVD

Description

The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary services as it incorrectly obtained application base url information from the executing http request which could be attacker controlled.

Affected (5)

1 product
Atlassian Gadgets
Configuration A
5 vulnerable · 6 platform
Vulnerable SoftwareAffected Versions
Atlassian
Before 4.2.37
From 4.3.0 to 4.3.14
From 4.3.2.0 to 4.3.2.4
From 4.4.0 to 4.4.12
From 5.0.0 to 5.0.1
Running on/withPlatform Versions
Atlassian
Data Center
From 8.13.3 to 8.14.1
Atlassian
Data Center
From 8.5.11 to 8.13.2
Atlassian
Jira Data Center
Version 8.15.0
Atlassian
Jira Server
From 8.13.3 to 8.14.1
Atlassian
Jira Server
From 8.5.11 to 8.13.2
Atlassian
Jira Server
Version 8.15.0

References (2)

Source: security@atlassian.com
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory

Timeline

No history available yet.