Atlassian Companion App vulnerabilities
2 known vulnerabilities affecting atlassian/companion_app.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2020-4019HIGHCVSS 7.8≥ unspecified, < 1.0.02020-06-01
CVE-2020-4019 [HIGH] CWE-426 CVE-2020-4019: The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local atta
The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local attackers to have the app run a different executable in place of the app's cmd.exe via a untrusted search path vulnerability.
cvelistv5nvd
CVE-2020-4020HIGHCVSS 7.2≥ unspecified, < 1.0.02020-06-01
CVE-2020-4020 [HIGH] CVE-2020-4020: The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote
The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who control a Confluence Server instance that the Companion App is connected to, execute arbitrary .exe files via a Protection Mechanism Failure.
cvelistv5nvd