- 
    
Bug
 - 
    Resolution: Fixed
 - 
    
High
 - 
    Companion-Legacy
 
- 
        Severity 2 - Major
 - 
        
 
The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who control a Confluence Server instance that the Companion App is connected to, execute arbitrary .exe files via a Protection Mechanism Failure.
Acknowledgements
Credit for finding this vulnerability goes to Johannes Hatting (UFST).