Uploaded image for project: 'HipChat'
  1. HipChat
  2. HCPUB-2980

Remote Code Execution via Image Uploads

This issue belongs to an archived project. You can view it, but you can't modify it. Learn more

XMLWordPrintable

    • Severity 1 - Critical

      Description

      An attacker with user level privileges could gain Remote Code Execution via a malicious image upload.

      Affected versions

      • All versions of HipChat Server before version 2.2.4 are affected by this vulnerability.

       

      Fix

      We have taken the following steps to address these issues:

       

      For additional details see the full advisory.

              Unassigned Unassigned
              mhart@atlassian.com Matt Hart (Inactive)
              Archiver:
              mandreacchio Michael Andreacchio

                Created:
                Updated:
                Resolved:
                Archived: