High severity7.2NVD Advisory· Published Jun 1, 2020· Updated Jun 17, 2026
CVE-2020-4020
CVE-2020-4020
Description
The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who control a Confluence Server instance that the Companion App is connected to, execute arbitrary .exe files via a Protection Mechanism Failure.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<1.0.0+ 1 more
- (no CPE)range: <1.0.0
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
1- jira.atlassian.com/browse/CONFSERVER-59733nvdVendor Advisory
News mentions
0No linked articles in our index yet.