CVE-2017-14585
Summary
| CVE | CVE-2017-14585 |
|---|---|
| State | PUBLISHED |
| Assigner | atlassian |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-11-27 16:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | A Server Side Request Forgery (SSRF) vulnerability could lead to remote code execution for authenticated administrators. This issue was introduced in version 2.2.0 of Hipchat Server and version 3.0.0 of Hipchat Data Center. Versions of Hipchat Server starting with 2.2.0 and before 2.2.6 are affected by this vulnerability. Versions of Hipchat Data Center starting with 3.0.0 and before 3.1.0 are affected. |
Risk And Classification
Primary CVSS: v3.0 7.2 HIGH from [email protected]
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.017530000 probability, percentile 0.827650000 (date 2026-05-14)
Problem Types: CWE-918 | Remote Code Execution
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 7.2 | HIGH | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 9 | AV:N/AC:L/Au:S/C:C/I:C/A:C |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
HighUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Atlassian | Hipchat Data Center | All | All | All | All |
| Application | Atlassian | Hipchat Server | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Atlassian | Hipchat Server | affected 2.2.0 <= version < 4.3 | Not specified |
| CNA | Atlassian | Hipchat Data Center | affected 3.0.0 <= version < 3.1.0 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [HCPUB-3526] Remote code execution in HipChat Server and Data Center via SSRF in 'admin' interface - CVE-2017-14585 - Create and track feature requests for Atlassian products. | af854a3a-2127-422b-91ae-364da2661108 | jira.atlassian.com | Issue Tracking, Vendor Advisory |
| Atlassian Hipchat Server and Data Center CVE-2017-14585 Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Hipchat Server Security Advisory 2017-11-22 - Atlassian Documentation | af854a3a-2127-422b-91ae-364da2661108 | confluence.atlassian.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.