Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g46m-x4q2-p642

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5

Описание

The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary services as it incorrectly obtained application base url information from the executing http request which could be attacker controlled.

The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary services as it incorrectly obtained application base url information from the executing http request which could be attacker controlled.

EPSS

Процентиль: 29%
0.00103
Низкий

5 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 5
nvd
почти 5 лет назад

The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary services as it incorrectly obtained application base url information from the executing http request which could be attacker controlled.

EPSS

Процентиль: 29%
0.00103
Низкий

5 Medium

CVSS3

Дефекты

CWE-918