CVE-2017-14585
HIGHHipchat Server <2.2.6, Hipchat Data Center <3.1.0 - SSRF
Title source: llmDescription
A Server Side Request Forgery (SSRF) vulnerability could lead to remote code execution for authenticated administrators. This issue was introduced in version 2.2.0 of Hipchat Server and version 3.0.0 of Hipchat Data Center. Versions of Hipchat Server starting with 2.2.0 and before 2.2.6 are affected by this vulnerability. Versions of Hipchat Data Center starting with 3.0.0 and before 3.1.0 are affected.
References (3)
Core 3
Core References
Issue Tracking, Vendor Advisory x_refsource_confirm
https://jira.atlassian.com/browse/HCPUB-3526
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/101945
Vendor Advisory x_refsource_confirm
https://confluence.atlassian.com/hc/hipchat-server-security-advisory-2017-11-22-939946293.html
Scores
CVSS v3
7.2
EPSS
0.0175
EPSS Percentile
82.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-918
Status
published
Products (4)
Atlassian/Hipchat Data Center
3.0.0 <= version < 3.1.0
Atlassian/Hipchat Server
2.2.0 <= version < 4.3
atlassian/hipchat_data_center
3.0.0 - 3.1.0
atlassian/hipchat_server
2.2.0 - 2.2.6
Published
Nov 27, 2017
Tracked Since
Feb 18, 2026