« Back to list

CVE-2020-36232

Status: ModifiedMedium (5)—

The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary services as it incorrectly obtained application base url information from the executing http request which could be attacker controlled.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2020-36232",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.1
      }
    ]
  },
  "affected": [
    {
      "source": "security@atlassian.com",
      "affectedData": [
        {
          "vendor": "Atlassian",
          "product": "Atlassian Gadgets",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "4.2.37",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.3.0",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "4.3.14",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.3.2.0",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "4.3.2.4",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.4.0",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "4.4.12",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "5.0.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-02-22T21:15:19.633",
  "references": [
    {
      "url": "https://jira.atlassian.com/browse/JRASERVER-72025",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security@atlassian.com"
    },
    {
      "url": "https://jira.atlassian.com/browse/JRASERVER-72025",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-918"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary services as it incorrectly obtained application base url information from the executing http request which could be attacker controlled."
    },
    {
      "lang": "es",
      "value": "La clase MessageBundleWhiteList de atlassian-gadgets versiones anteriores a 4.2.37, desde versiones 4.3.0 anteriores a 4.3.14, desde versiones 4.3.2.0 anteriores a 4.3.2.4, desde versiones 4.4.0 anteriores a 4.4.12 y desde versiones 5.0.0 anteriores a 5.0.1, permitió búsquedas de DNS no previstas y peticiones a servicios arbitrarios, ya que obtuvo incorrectamente una información de la URL base de la aplicación desde la petición http en ejecución que podría ser controlada por el atacante"
    }
  ],
  "lastModified": "2026-06-17T03:15:10.397",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:atlassian:atlassian-gadgets:*:*:*:*:*:atlassian:*:*",
              "vulnerable": true,
              "matchCriteriaId": "18AB03E6-F6A0-48B8-803E-29CDDE446CD2",
              "versionEndExcluding": "4.2.37"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:atlassian-gadgets:*:*:*:*:*:atlassian:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D66B66A9-64B7-4FD4-874D-D87A4D575944",
              "versionEndExcluding": "4.3.14",
              "versionStartIncluding": "4.3.0"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:atlassian-gadgets:*:*:*:*:*:atlassian:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1C0EF3C6-EAB2-4D43-87AF-AA5B92E315B1",
              "versionEndExcluding": "4.3.2.4",
              "versionStartIncluding": "4.3.2.0"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:atlassian-gadgets:*:*:*:*:*:atlassian:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1F77F1E1-D485-4010-86F6-2EDE6AEBD544",
              "versionEndExcluding": "4.4.12",
              "versionStartIncluding": "4.4.0"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:atlassian-gadgets:*:*:*:*:*:atlassian:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D9CCD8A-C666-4C05-A423-D0416D210DD3",
              "versionEndExcluding": "5.0.1",
              "versionStartIncluding": "5.0.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:atlassian:data_center:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A7AC2E8F-5A59-4F65-B8F2-CF86875D5CB5",
              "versionEndExcluding": "8.13.2",
              "versionStartIncluding": "8.5.11"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:data_center:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0FD6D137-B726-43EF-AF46-FBC641301CBA",
              "versionEndExcluding": "8.14.1",
              "versionStartIncluding": "8.13.3"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:jira_data_center:8.15.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "058961D9-AF6A-4966-88D8-35609DA27F11"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "58079191-F6B7-4E6A-9285-A6ACB0A90B35",
              "versionEndExcluding": "8.13.2",
              "versionStartIncluding": "8.5.11"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FB217AB4-918C-443D-81B1-BAD50CB4FA27",
              "versionEndExcluding": "8.14.1",
              "versionStartIncluding": "8.13.3"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:jira_server:8.15.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "BE0A11AB-40CE-49C5-B358-59DD5E791CA1"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security@atlassian.com"
}