cbcvebase.
CVE-2020-4020
published 2020-06-01

CVE-2020-4020: The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who control a Confluence Server instance that…

high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who control a Confluence Server instance that the Companion App is connected to, execute arbitrary .exe files via a Protection Mechanism Failure.

Affected

2 ranges
VendorProductVersion rangeFixed in
atlassiancompanion< 1.0.01.0.0
atlassiancompanion_app>= unspecified < 1.0.01.0.0