CVE-2020-36232 Information
Description
The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37 from version 4.3.0 before 4.3.14 from version 4.3.2.0 before 4.3.2.4 from version 4.4.0 before 4.4.12 and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary services as it incorrectly obtained application base url information from the executing http request which could be attacker controlled.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Reference
https://jira.atlassian.com/browse/JRASERVER-72025 The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37 from version 4.3.0 before 4.3.14 from version 4.3.2.0 before 4.3.2.4 from version 4.4.0 before 4.4.12 and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary services as it incorrectly obtained application base url information from the executing http request which could be attacker controlled.
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.0
Share on: