CVE-2020-36232
Published: Feb 22, 2021
Modified: Sep 17, 2024
Description
The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary services as it incorrectly obtained application base url information from the executing http request which could be attacker controlled.
| Vendor | Product | Versions |
|---|---|---|
Atlassian | Atlassian Gadgets | affected unspecified - < 4.2.37affected 4.3.0 - < unspecifiedaffected unspecified - < 4.3.14affected 4.3.2.0 - < unspecifiedaffected unspecified - < 4.3.2.4+3 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now