Uploaded image for project: 'HipChat'
  1. HipChat
  2. HCPUB-2980

Remote Code Execution via Image Uploads

This issue belongs to an archived project. You can view it, but you can't modify it. Learn more

XMLWordPrintable

    • Severity 1 - Critical

      Description

      An attacker with user level privileges could gain Remote Code Execution via a malicious image upload.

      Affected versions

      • All versions of HipChat Server before version 2.2.4 are affected by this vulnerability.

       

      Fix

      We have taken the following steps to address these issues:

       

      For additional details see the full advisory.

            Unassigned Unassigned
            mhart@atlassian.com Matt Hart (Inactive)
            Archiver:
            mandreacchio Michael Andreacchio

              Created:
              Updated:
              Resolved:
              Archived: