CVE-2020-36232
CVE-2020-36232
Vexday Risk Score
3Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS —EPSS 1.0%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
22 fev 2021Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary services as it incorrectly obtained application base url information from the executing http request which could be attacker controlled.
Produtos afetados
Atlassian · Atlassian GadgetsQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →