CVE-2017-14585
Last modified
CVE-2017-14585 is a vulnerability of currently unknown severity. A Server Side Request Forgery (SSRF) vulnerability could lead to remote code execution for authenticated administrators. This issue was introduced in version 2.2.0 of Hipchat Server and version 3.0.0 of Hipchat Data Center. EPSS estimates a 4.37% chance of exploitation in the next 30 days.
Description
A Server Side Request Forgery (SSRF) vulnerability could lead to remote code execution for authenticated administrators. This issue was introduced in version 2.2.0 of Hipchat Server and version 3.0.0 of Hipchat Data Center. Versions of Hipchat Server starting with 2.2.0 and before 2.2.6 are affected by this vulnerability. Versions of Hipchat Data Center starting with 3.0.0 and before 3.1.0 are affected.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Hipchat Data Center | >= 3.0.0, < 3.1.0 |
| Atlassian | Hipchat Server | >= 2.2.0, < 2.2.6 |
References
- http://www.securityfocus.com/bid/101945Third Party Advisory, VDB Entry
- https://jira.atlassian.com/browse/HCPUB-3526Issue Tracking, Vendor Advisory
- http://www.securityfocus.com/bid/101945Third Party Advisory, VDB Entry
- https://jira.atlassian.com/browse/HCPUB-3526Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-14585?
How severe is CVE-2017-14585?
How do I fix CVE-2017-14585?
Are you affected by CVE-2017-14585?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
