Remote Code Execution via Image Uploads

This issue belongs to an archived project. You can view it, but you can't modify it. Learn more

XMLWordPrintable

    • Severity 1 - Critical

      Description

      An attacker with user level privileges could gain Remote Code Execution via a malicious image upload.

      Affected versions

      • All versions of HipChat Server before version 2.2.4 are affected by this vulnerability.

       

      Fix

      We have taken the following steps to address these issues:

       

      For additional details see the full advisory.

              Assignee:
              Unassigned
              Reporter:
              Matt Hart (Inactive)
              Archiver:
              Michael Andreacchio

                Created:
                Updated:
                Resolved:
                Archived: