Server Side Request Forgery Vulnerability in Hipchat Server and Data Center by Atlassian
CVE-2017-14585
7.2HIGH
Key Information:
- Vendor
Atlassian
- Vendor
- CVE Published:
- 27 November 2017
What is CVE-2017-14585?
A Server Side Request Forgery (SSRF) vulnerability exists in Hipchat Server and Hipchat Data Center that can be exploited by authenticated administrators. This vulnerability allows attackers to craft requests that could lead to remote code execution. Specifically, the flaw was introduced in Hipchat Server version 2.2.0 and version 3.0.0 of Hipchat Data Center, affecting server versions up to 2.2.5 and data center versions up to 3.0.9. Administrators are advised to update their applications to mitigate potential risk.
Affected Version(s)
Hipchat Data Center 3.0.0 <= version < 3.1.0
Hipchat Server 2.2.0 <= version < 4.3