CVE Database
/

CVE-2020-36232

Back to search

CVE-2020-36232

Published: Feb 22, 2021

Modified: Sep 17, 2024

PUBLISHED

Description

The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary services as it incorrectly obtained application base url information from the executing http request which could be attacker controlled.

VendorProductVersions

Atlassian

Atlassian Gadgets

affected
unspecified - < 4.2.37
affected
4.3.0 - < unspecified
affected
unspecified - < 4.3.14
affected
4.3.2.0 - < unspecified
affected
unspecified - < 4.3.2.4

+3 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now