CVE-2020-4020: High severity Atlassian Companion vulnerability
Published Jun 1, 2020
·Updated
The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who control a Confluence Server instance that the Companion App is connected to, execute arbitrary .exe files via a Protection Mechanism Failure.
Affected Software
1 affected component
Atlassian Companion<1.0.0
Event History
Jun 1, 2020
CVE Published
via MITRE·06:35 AM
Data Sourced
via MITRE·06:35 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-4020.
2
What is the severity of CVE-2020-4020?
The severity of CVE-2020-4020 is high with a severity value of 7.2.
3
What is the affected software?
The affected software is the Atlassian Companion App before version 1.0.0.
4
How can remote attackers exploit CVE-2020-4020?
Remote attackers can exploit CVE-2020-4020 by executing arbitrary .exe files via a Protection Mechanism Failure, if they control a connected Confluence Server instance.
5
Is there a fix available for CVE-2020-4020?
Yes, updating to version 1.0.0 or later of the Atlassian Companion App fixes CVE-2020-4020.