CVE-2019-20406
published 2020-02-06CVE-2019-20406: The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local…
PriorityP433high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.48%
38.4th percentile
The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a directory in the global path environmental variable variable to inject code & escalate their privileges via a DLL hijacking vulnerability.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | confluence | < 7.0.5 | 7.0.5 |
| atlassian | confluence_data_center | >= 7.1.0 < unspecified | unspecified |
| atlassian | confluence_data_center | >= unspecified < 7.0.5 | 7.0.5 |
| atlassian | confluence_data_center | >= unspecified < 7.1.1 | 7.1.1 |
| atlassian | confluence_server | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gw5q-m62q-j9vf: The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7
ghsa_unreviewed·2022-05-24
CVE-2019-20406 [MEDIUM] CWE-426 GHSA-gw5q-m62q-j9vf: The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7
The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a directory in the global path environmental variable variable to inject code & escalate their privileges via a DLL hijacking vulnerability.
OSV
python2.7, python3.5, python3.6, python3.7 vulnerabilities
osv·2019-09-09·CVSS 7.5
CVE-2018-20406 python2.7, python3.5, python3.6, python3.7 vulnerabilities
python2.7, python3.5, python3.6, python3.7 vulnerabilities
It was discovered that Python incorrectly handled certain pickle files. An
attacker could possibly use this issue to consume memory, leading to a
denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu
18.04 LTS. (CVE-2018-20406)
It was discovered that Python incorrectly validated the domain when
handling cookies. An attacker could possibly trick Python into sending
cookies to the wrong domain. (CVE-2018-20852)
Jonathan Birch and Panayiotis Panayiotou discovered that Python incorrectly
handled Unicode encoding during NFKC normalization. An attacker could
possibly use this issue to obtain sensitive information. (CVE-2019-9636,
CVE-2019-10160)
Colin Read and Nicolas Edet discovered that Python incorrectly handled
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-02-06
Published