CVE-2017-7357

Severity
9.1CRITICAL
EPSS
2.2%
top 15.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 14
Latest updateMay 14

Description

Hipchat Server before 2.2.3 allows remote authenticated users with Server Administrator level privileges to execute arbitrary code by importing a file.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HExploitability: 2.3 | Impact: 6.0

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-r477-2fhj-xjjw: Hipchat Server before 22022-05-14
CVEList
CVE-2017-7357: Hipchat Server before 22017-04-14
CVE-2017-7357 (CRITICAL CVSS 9.1) | Hipchat Server before 2.2.3 allows | cvebase.io