High severity7.2NVD Advisory· Published Nov 27, 2017· Updated May 13, 2026
CVE-2017-14585
CVE-2017-14585
Description
A Server Side Request Forgery (SSRF) vulnerability could lead to remote code execution for authenticated administrators. This issue was introduced in version 2.2.0 of Hipchat Server and version 3.0.0 of Hipchat Data Center. Versions of Hipchat Server starting with 2.2.0 and before 2.2.6 are affected by this vulnerability. Versions of Hipchat Data Center starting with 3.0.0 and before 3.1.0 are affected.
Affected products
2- Atlassian/Hipchat Data Centerv5Range: 3.0.0 <= version < 3.1.0
- Atlassian/Hipchat Serverv5Range: 2.2.0 <= version < 4.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/101945nvdThird Party AdvisoryVDB Entry
- confluence.atlassian.com/hc/hipchat-server-security-advisory-2017-11-22-939946293.htmlnvdVendor Advisory
- jira.atlassian.com/browse/HCPUB-3526nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.