CVE-2020-36232: SSRF
The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary services as it incorrectly obtained application base url information from the executing http request which could be attacker controlled.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-36232.
What is the severity of CVE-2020-36232?
The severity of CVE-2020-36232 is medium.
What software versions are affected by CVE-2020-36232?
The software versions affected by CVE-2020-36232 are: atlassian-gadgets versions before 4.2.37, from version 4.3.0 to version 4.3.14, from version 4.3.2.0 to version 4.3.2.4, from version 4.4.0 to version 4.4.12, and from version 5.0.0 to version 5.0.1.
What is the description of CVE-2020-36232?
CVE-2020-36232 is a vulnerability in the MessageBundleWhiteList class of atlassian-gadgets that allows unexpected DNS lookups and requests to arbitrary services.
How can I fix CVE-2020-36232?
To fix CVE-2020-36232, update the atlassian-gadgets software to version 4.2.37 or higher.