CVE-2017-14585

HIGH

Hipchat Server <2.2.6, Hipchat Data Center <3.1.0 - SSRF

Title source: llm
STIX 2.1

Description

A Server Side Request Forgery (SSRF) vulnerability could lead to remote code execution for authenticated administrators. This issue was introduced in version 2.2.0 of Hipchat Server and version 3.0.0 of Hipchat Data Center. Versions of Hipchat Server starting with 2.2.0 and before 2.2.6 are affected by this vulnerability. Versions of Hipchat Data Center starting with 3.0.0 and before 3.1.0 are affected.

References (3)

Core 3
Core References
Issue Tracking, Vendor Advisory x_refsource_confirm
https://jira.atlassian.com/browse/HCPUB-3526
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/101945

Scores

CVSS v3 7.2
EPSS 0.0175
EPSS Percentile 82.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-918
Status published
Products (4)
Atlassian/Hipchat Data Center 3.0.0 <= version < 3.1.0
Atlassian/Hipchat Server 2.2.0 <= version < 4.3
atlassian/hipchat_data_center 3.0.0 - 3.1.0
atlassian/hipchat_server 2.2.0 - 2.2.6
Published Nov 27, 2017
Tracked Since Feb 18, 2026