Vulnerability Description
The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local attackers to have the app run a different executable in place of the app's cmd.exe via a untrusted search path vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Companion | < 1.0.0 |
Related Weaknesses (CWE)
References
- https://jira.atlassian.com/browse/CONFSERVER-59734Vendor Advisory
- https://jira.atlassian.com/browse/CONFSERVER-59734Vendor Advisory
FAQ
What is CVE-2020-4019?
CVE-2020-4019 is a vulnerability with a CVSS score of 7.8 (HIGH). The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local attackers to have the app run a different executable in place of the app's cmd.exe via a untrusted searc...
How severe is CVE-2020-4019?
CVE-2020-4019 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-4019?
Check the references section above for vendor advisories and patch information. Affected products include: Atlassian Companion.