-
Bug
-
Resolution: Fixed
-
High
-
Companion-Legacy
-
Severity 2 - Major
-
The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who control a Confluence Server instance that the Companion App is connected to, execute arbitrary .exe files via a Protection Mechanism Failure.
Acknowledgements
Credit for finding this vulnerability goes to Johannes Hatting (UFST).
This is an independent assessment and you should evaluate its applicability to your own IT environment.
CVSS v3 score: 8.4 => High severity
Exploitability Metrics
Scope Metric
Impact Metrics
https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H