Remote Code Execution via Image Uploads

This issue belongs to an archived project. You can view it, but you can't modify it. Learn more

XMLWordPrintable

    • Severity 1 - Critical

      Description

      An attacker with user level privileges could gain Remote Code Execution via a malicious image upload.

      Affected versions

      • All versions of HipChat Server before version 2.2.4 are affected by this vulnerability.

       

      Fix

      We have taken the following steps to address these issues:

       

      For additional details see the full advisory.

            Assignee:
            Unassigned
            Reporter:
            Matt Hart (Inactive)
            Archiver:
            Michael Andreacchio

              Created:
              Updated:
              Resolved:
              Archived: