← Back to CVE List

CVE-2020-36232

Published: 2021-02-22T21:15Z
Last Modified: 2024-11-21T05:29Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary services as it incorrectly obtained application base url information from the executing http request which could be attacker controlled. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt