📦

companion

Vendor: atlassian

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 1 Remote Access
Total CVEs 5 Total Indexed
Avg. EPSS 6.77% Exploit Prob.
Latest CVE CVE-2024-22129 Feb 13

Security Vulnerability Index

Page 1 / 1
5.4 CVSS

SAP Companion - version <3.1.38, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve the sensitive information and cause minor impact on the integrity of the web application.

EPSS: 0.32%
9.8 CVSS
CVE-2023-22524
RCE Exploit Found

Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code.

EPSS: 24.73%
7.2 CVSS

The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who control a Confluence Server instance that the Companion App is connected to, execute arbitrary .exe files via a Protection Mechanism Failure.

EPSS: 1.67%
7.8 CVSS

The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local attackers to have the app run a different executable in place of the app's cmd.exe via a untrusted search path vulnerability.

EPSS: 0.36%