CVE-2020-4019: High severity atlassian companion vulnerability
Published Jun 1, 2020
·Updated
The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local attackers to have the app run a different executable in place of the app's cmd.exe via a untrusted search path vulnerability.
Affected Software
1 affected component
Atlassian Companion<1.0.0
Event History
Jun 1, 2020
CVE Published
via MITRE·06:35 AM
Data Sourced
via MITRE·06:35 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the file editing functionality in the Atlassian Companion App?
The vulnerability ID is CVE-2020-4019.
2
What is the severity of CVE-2020-4019?
The severity of CVE-2020-4019 is high with a CVSS score of 7.8.
3
What is the affected software for CVE-2020-4019?
The affected software is the Atlassian Companion App before version 1.0.0.
4
How does CVE-2020-4019 affect the Atlassian Companion App?
CVE-2020-4019 allows local attackers to have the app run a different executable in place of the app's cmd.exe via an untrusted search path vulnerability.
5
Is there a fix for CVE-2020-4019?
Yes, the fix for CVE-2020-4019 is to update the Atlassian Companion App to version 1.0.0 or later.