Server Side Request Forgery Vulnerability in Hipchat Server and Data Center by Atlassian
CVE-2017-14585
7.2HIGH
Key Information:
- Vendor
- Atlassian
- Vendor
- CVE Published:
- 27 November 2017
Summary
A Server Side Request Forgery (SSRF) vulnerability exists in Hipchat Server and Hipchat Data Center that can be exploited by authenticated administrators. This vulnerability allows attackers to craft requests that could lead to remote code execution. Specifically, the flaw was introduced in Hipchat Server version 2.2.0 and version 3.0.0 of Hipchat Data Center, affecting server versions up to 2.2.5 and data center versions up to 3.0.9. Administrators are advised to update their applications to mitigate potential risk.
Affected Version(s)
Hipchat Data Center 3.0.0 <= version < 3.1.0
Hipchat Server 2.2.0 <= version < 4.3
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved