CVE-2020-36232
Status: ModifiedMedium (5)—
The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary services as it incorrectly obtained application base url information from the executing http request which could be attacker controlled.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
- Base score: 5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.08%
- Percentile among all scored CVEs: 64
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-918
References
Raw JSON (NVD)
Show
{
"id": "CVE-2020-36232",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 3.1
}
]
},
"affected": [
{
"source": "security@atlassian.com",
"affectedData": [
{
"vendor": "Atlassian",
"product": "Atlassian Gadgets",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "4.2.37",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.3.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "4.3.14",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.3.2.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "4.3.2.4",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.4.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "4.4.12",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.0.0"
}
]
}
]
}
],
"published": "2021-02-22T21:15:19.633",
"references": [
{
"url": "https://jira.atlassian.com/browse/JRASERVER-72025",
"tags": [
"Issue Tracking",
"Patch",
"Vendor Advisory"
],
"source": "security@atlassian.com"
},
{
"url": "https://jira.atlassian.com/browse/JRASERVER-72025",
"tags": [
"Issue Tracking",
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-918"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary services as it incorrectly obtained application base url information from the executing http request which could be attacker controlled."
},
{
"lang": "es",
"value": "La clase MessageBundleWhiteList de atlassian-gadgets versiones anteriores a 4.2.37, desde versiones 4.3.0 anteriores a 4.3.14, desde versiones 4.3.2.0 anteriores a 4.3.2.4, desde versiones 4.4.0 anteriores a 4.4.12 y desde versiones 5.0.0 anteriores a 5.0.1, permitió búsquedas de DNS no previstas y peticiones a servicios arbitrarios, ya que obtuvo incorrectamente una información de la URL base de la aplicación desde la petición http en ejecución que podría ser controlada por el atacante"
}
],
"lastModified": "2026-06-17T03:15:10.397",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:atlassian:atlassian-gadgets:*:*:*:*:*:atlassian:*:*",
"vulnerable": true,
"matchCriteriaId": "18AB03E6-F6A0-48B8-803E-29CDDE446CD2",
"versionEndExcluding": "4.2.37"
},
{
"criteria": "cpe:2.3:a:atlassian:atlassian-gadgets:*:*:*:*:*:atlassian:*:*",
"vulnerable": true,
"matchCriteriaId": "D66B66A9-64B7-4FD4-874D-D87A4D575944",
"versionEndExcluding": "4.3.14",
"versionStartIncluding": "4.3.0"
},
{
"criteria": "cpe:2.3:a:atlassian:atlassian-gadgets:*:*:*:*:*:atlassian:*:*",
"vulnerable": true,
"matchCriteriaId": "1C0EF3C6-EAB2-4D43-87AF-AA5B92E315B1",
"versionEndExcluding": "4.3.2.4",
"versionStartIncluding": "4.3.2.0"
},
{
"criteria": "cpe:2.3:a:atlassian:atlassian-gadgets:*:*:*:*:*:atlassian:*:*",
"vulnerable": true,
"matchCriteriaId": "1F77F1E1-D485-4010-86F6-2EDE6AEBD544",
"versionEndExcluding": "4.4.12",
"versionStartIncluding": "4.4.0"
},
{
"criteria": "cpe:2.3:a:atlassian:atlassian-gadgets:*:*:*:*:*:atlassian:*:*",
"vulnerable": true,
"matchCriteriaId": "8D9CCD8A-C666-4C05-A423-D0416D210DD3",
"versionEndExcluding": "5.0.1",
"versionStartIncluding": "5.0.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:atlassian:data_center:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A7AC2E8F-5A59-4F65-B8F2-CF86875D5CB5",
"versionEndExcluding": "8.13.2",
"versionStartIncluding": "8.5.11"
},
{
"criteria": "cpe:2.3:a:atlassian:data_center:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0FD6D137-B726-43EF-AF46-FBC641301CBA",
"versionEndExcluding": "8.14.1",
"versionStartIncluding": "8.13.3"
},
{
"criteria": "cpe:2.3:a:atlassian:jira_data_center:8.15.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "058961D9-AF6A-4966-88D8-35609DA27F11"
},
{
"criteria": "cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "58079191-F6B7-4E6A-9285-A6ACB0A90B35",
"versionEndExcluding": "8.13.2",
"versionStartIncluding": "8.5.11"
},
{
"criteria": "cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "FB217AB4-918C-443D-81B1-BAD50CB4FA27",
"versionEndExcluding": "8.14.1",
"versionStartIncluding": "8.13.3"
},
{
"criteria": "cpe:2.3:a:atlassian:jira_server:8.15.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BE0A11AB-40CE-49C5-B358-59DD5E791CA1"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "security@atlassian.com"
}