"-Synchronized-Data."

This commit is contained in:
CVE Team 2021-02-22 21:00:59 +00:00
parent 56dddc3f7d
commit 5e2d5be9b2
No known key found for this signature in database
GPG Key ID: 5708902F06FEF743
7 changed files with 105 additions and 209 deletions

View File

@ -244,11 +244,6 @@
"url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-17136",
"refsource": "MISC",
"name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-17136"
},
{
"refsource": "MISC",
"name": "http://packetstormsecurity.com/files/160919/Cloud-Filter-Arbitrary-File-Creation-Privilege-Escalation.html",
"url": "http://packetstormsecurity.com/files/160919/Cloud-Filter-Arbitrary-File-Creation-Privilege-Escalation.html"
}
]
}

View File

@ -9,38 +9,27 @@
"vendor": {
"vendor_data": [
{
"vendor_name": "Atlassian",
"product": {
"product_data": [
{
"product_name": "Confluence Server",
"product_name": "Confluence Server, Confluence Data Center",
"version": {
"version_data": [
{
"version_value": "6.13.18",
"version_affected": "<"
"version_value": "before version 6.13.18"
},
{
"version_value": "6.14.0",
"version_affected": ">="
"version_value": "from 6.14.0 before 7.4.6"
},
{
"version_value": "7.4.6",
"version_affected": "<"
},
{
"version_value": "7.5.0",
"version_affected": ">="
},
{
"version_value": "7.8.3",
"version_affected": "<"
"version_value": "from 7.5.0 before 7.8.3"
}
]
}
}
]
},
"vendor_name": "Atlassian"
}
}
]
}

View File

@ -9,65 +9,27 @@
"vendor": {
"vendor_data": [
{
"vendor_name": "Atlassian",
"product": {
"product_data": [
{
"product_name": "Jira Server",
"product_name": "Jira Server, Jira Data Center",
"version": {
"version_data": [
{
"version_value": "8.5.11",
"version_affected": "<"
"version_value": "before version 8.5.11"
},
{
"version_value": "8.6.0",
"version_affected": ">="
"version_value": "from 8.6.0 before 8.13.3"
},
{
"version_value": "8.13.3",
"version_affected": "<"
},
{
"version_value": "8.14.0",
"version_affected": ">="
},
{
"version_value": "8.15.0",
"version_affected": "<"
}
]
}
},
{
"product_name": "Jira Data Center",
"version": {
"version_data": [
{
"version_value": "8.5.11",
"version_affected": "<"
},
{
"version_value": "8.6.0",
"version_affected": ">="
},
{
"version_value": "8.13.3",
"version_affected": "<"
},
{
"version_value": "8.14.0",
"version_affected": ">="
},
{
"version_value": "8.15.0",
"version_affected": "<"
"version_value": "from 8.14.0 before 8.15.0"
}
]
}
}
]
},
"vendor_name": "Atlassian"
}
}
]
}

View File

@ -1,90 +1,75 @@
{
"CVE_data_meta": {
"ASSIGNER": "security@atlassian.com",
"DATE_PUBLIC": "2021-01-28T00:00:00",
"ID": "CVE-2020-36232",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Atlassian Gadgets",
"version": {
"version_data": [
{
"version_value": "4.2.37",
"version_affected": "<"
},
{
"version_value": "4.3.0",
"version_affected": ">="
},
{
"version_value": "4.3.14",
"version_affected": "<"
},
{
"version_value": "4.3.2.0",
"version_affected": ">="
},
{
"version_value": "4.3.2.4",
"version_affected": "<"
},
{
"version_value": "4.4.0",
"version_affected": ">="
},
{
"version_value": "4.4.12",
"version_affected": "<"
},
{
"version_value": "5.0.0",
"version_affected": "="
}
]
}
}
]
},
"vendor_name": "Atlassian"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary services as it incorrectly obtained application base url information from the executing http request which could be attacker controlled."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Security Misconfiguration"
}
"CVE_data_meta": {
"ASSIGNER": "security@atlassian.com",
"DATE_PUBLIC": "2021-01-28T00:00:00",
"ID": "CVE-2020-36232",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "Atlassian",
"product": {
"product_data": [
{
"product_name": "Atlassian Gadgets",
"version": {
"version_data": [
{
"version_value": "before version 4.2.37"
},
{
"version_value": "from version 4.3.0 before 4.3.14"
},
{
"version_value": "from version 4.3.2.0 before 4.3.2.4"
},
{
"version_value": "from version 4.4.0 before 4.4.12"
},
{
"version_value": "from version 5.0.0 before 5.0.1"
}
]
}
}
]
}
}
]
}
]
},
"references": {
"reference_data": [
{
"url": "https://jira.atlassian.com/browse/JRASERVER-72025"
}
]
}
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary services as it incorrectly obtained application base url information from the executing http request which could be attacker controlled."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Security Misconfiguration"
}
]
}
]
},
"references": {
"reference_data": [
{
"url": "https://jira.atlassian.com/browse/JRASERVER-72025",
"refsource": "MISC",
"name": "https://jira.atlassian.com/browse/JRASERVER-72025"
}
]
}
}

View File

@ -9,38 +9,27 @@
"vendor": {
"vendor_data": [
{
"vendor_name": "Atlassian",
"product": {
"product_data": [
{
"product_name": "Bitbucket Server and Data Center",
"product_name": "Bitbucket Server, Data Center",
"version": {
"version_data": [
{
"version_value": "6.10.9",
"version_affected": "<"
"version_value": "before version 6.10.9"
},
{
"version_value": "7.0.0",
"version_affected": ">="
"version_value": "7.x before 7.6.4"
},
{
"version_value": "7.6.4",
"version_affected": "<"
},
{
"version_value": "7.7.0",
"version_affected": ">="
},
{
"version_value": "7.10.1",
"version_affected": "<"
"version_value": "from version 7.7.0 before 7.10.1"
}
]
}
}
]
},
"vendor_name": "Atlassian"
}
}
]
}
@ -74,6 +63,11 @@
"url": "https://jira.atlassian.com/browse/BSERV-12753",
"refsource": "MISC",
"name": "https://jira.atlassian.com/browse/BSERV-12753"
},
{
"refsource": "CERT-VN",
"name": "VU#240785",
"url": "https://www.kb.cert.org/vuls/id/240785"
}
]
}

View File

@ -9,48 +9,24 @@
"vendor": {
"vendor_data": [
{
"vendor_name": "Atlassian",
"product": {
"product_data": [
{
"product_name": "Confluence Server",
"product_name": "Confluence Server, Confluence Data Center",
"version": {
"version_data": [
{
"version_value": "7.4.5",
"version_affected": "<"
"version_value": "before version 7.4.5"
},
{
"version_value": "7.5.0",
"version_affected": ">="
},
{
"version_value": "7.5.1",
"version_affected": "<"
}
]
}
},{
"product_name": "Confluence Data Center",
"version": {
"version_data": [
{
"version_value": "7.4.5",
"version_affected": "<"
},
{
"version_value": "7.5.0",
"version_affected": ">="
},
{
"version_value": "7.5.1",
"version_affected": "<"
"version_value": "from version 7.5.0 before 7.5.1"
}
]
}
}
]
},
"vendor_name": "Atlassian"
}
}
]
}

View File

@ -9,6 +9,7 @@
"vendor": {
"vendor_data": [
{
"vendor_name": "Atlassian",
"product": {
"product_data": [
{
@ -16,19 +17,13 @@
"version": {
"version_data": [
{
"version_value": "0.0.3",
"version_affected": ">="
},
{
"version_value": "2.0.15",
"version_affected": "<"
"version_value": "from 0.0.3 before 2.0.15"
}
]
}
}
]
},
"vendor_name": "Atlassian"
}
}
]
}