CVE-2020-36232
Estado: ModificadaMedia (5)—
The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary services as it incorrectly obtained application base url information from the executing http request which could be attacker controlled.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.08%
- Percentil entre todas las CVEs puntuadas: 64
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-918
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-36232",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 3.1
}
]
},
"affected": [
{
"source": "security@atlassian.com",
"affectedData": [
{
"vendor": "Atlassian",
"product": "Atlassian Gadgets",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "4.2.37",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.3.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "4.3.14",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.3.2.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "4.3.2.4",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.4.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "4.4.12",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.0.0"
}
]
}
]
}
],
"published": "2021-02-22T21:15:19.633",
"references": [
{
"url": "https://jira.atlassian.com/browse/JRASERVER-72025",
"tags": [
"Issue Tracking",
"Patch",
"Vendor Advisory"
],
"source": "security@atlassian.com"
},
{
"url": "https://jira.atlassian.com/browse/JRASERVER-72025",
"tags": [
"Issue Tracking",
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-918"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary services as it incorrectly obtained application base url information from the executing http request which could be attacker controlled."
},
{
"lang": "es",
"value": "La clase MessageBundleWhiteList de atlassian-gadgets versiones anteriores a 4.2.37, desde versiones 4.3.0 anteriores a 4.3.14, desde versiones 4.3.2.0 anteriores a 4.3.2.4, desde versiones 4.4.0 anteriores a 4.4.12 y desde versiones 5.0.0 anteriores a 5.0.1, permitió búsquedas de DNS no previstas y peticiones a servicios arbitrarios, ya que obtuvo incorrectamente una información de la URL base de la aplicación desde la petición http en ejecución que podría ser controlada por el atacante"
}
],
"lastModified": "2026-06-17T03:15:10.397",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:atlassian:atlassian-gadgets:*:*:*:*:*:atlassian:*:*",
"vulnerable": true,
"matchCriteriaId": "18AB03E6-F6A0-48B8-803E-29CDDE446CD2",
"versionEndExcluding": "4.2.37"
},
{
"criteria": "cpe:2.3:a:atlassian:atlassian-gadgets:*:*:*:*:*:atlassian:*:*",
"vulnerable": true,
"matchCriteriaId": "D66B66A9-64B7-4FD4-874D-D87A4D575944",
"versionEndExcluding": "4.3.14",
"versionStartIncluding": "4.3.0"
},
{
"criteria": "cpe:2.3:a:atlassian:atlassian-gadgets:*:*:*:*:*:atlassian:*:*",
"vulnerable": true,
"matchCriteriaId": "1C0EF3C6-EAB2-4D43-87AF-AA5B92E315B1",
"versionEndExcluding": "4.3.2.4",
"versionStartIncluding": "4.3.2.0"
},
{
"criteria": "cpe:2.3:a:atlassian:atlassian-gadgets:*:*:*:*:*:atlassian:*:*",
"vulnerable": true,
"matchCriteriaId": "1F77F1E1-D485-4010-86F6-2EDE6AEBD544",
"versionEndExcluding": "4.4.12",
"versionStartIncluding": "4.4.0"
},
{
"criteria": "cpe:2.3:a:atlassian:atlassian-gadgets:*:*:*:*:*:atlassian:*:*",
"vulnerable": true,
"matchCriteriaId": "8D9CCD8A-C666-4C05-A423-D0416D210DD3",
"versionEndExcluding": "5.0.1",
"versionStartIncluding": "5.0.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:atlassian:data_center:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A7AC2E8F-5A59-4F65-B8F2-CF86875D5CB5",
"versionEndExcluding": "8.13.2",
"versionStartIncluding": "8.5.11"
},
{
"criteria": "cpe:2.3:a:atlassian:data_center:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0FD6D137-B726-43EF-AF46-FBC641301CBA",
"versionEndExcluding": "8.14.1",
"versionStartIncluding": "8.13.3"
},
{
"criteria": "cpe:2.3:a:atlassian:jira_data_center:8.15.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "058961D9-AF6A-4966-88D8-35609DA27F11"
},
{
"criteria": "cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "58079191-F6B7-4E6A-9285-A6ACB0A90B35",
"versionEndExcluding": "8.13.2",
"versionStartIncluding": "8.5.11"
},
{
"criteria": "cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "FB217AB4-918C-443D-81B1-BAD50CB4FA27",
"versionEndExcluding": "8.14.1",
"versionStartIncluding": "8.13.3"
},
{
"criteria": "cpe:2.3:a:atlassian:jira_server:8.15.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BE0A11AB-40CE-49C5-B358-59DD5E791CA1"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "security@atlassian.com"
}