CVE-2015-5603
medium · 6.5The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecified vectors, related to "Velocity Template Injection Vulnerability."
6.5
CVSS
59.3%
EPSS (exploit prob.)
99th
EPSS percentile
2015-09-21
Published
AV:N/AC:L/Au:S/C:P/I:P/A:P
Weaknesses
CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| atlassian | hipchat | <= 6.29.2 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/133401/Jira-HipChat-For-Jira-Java-Code-Execution.html
- http://www.rapid7.com/db/modules/exploit/multi/http/jira_hipchat_template
- http://www.securityfocus.com/archive/1/536374/100/0/threaded
- https://confluence.atlassian.com/jira/jira-and-hipchat-for-jira-plugin-security-advisory-2015-08-26-776650785.html
- https://www.exploit-db.com/exploits/38551/
- https://www.exploit-db.com/exploits/38905/
- http://packetstormsecurity.com/files/133401/Jira-HipChat-For-Jira-Java-Code-Execution.html
- http://www.rapid7.com/db/modules/exploit/multi/http/jira_hipchat_template
- http://www.securityfocus.com/archive/1/536374/100/0/threaded
- https://confluence.atlassian.com/jira/jira-and-hipchat-for-jira-plugin-security-advisory-2015-08-26-776650785.html
- https://www.exploit-db.com/exploits/38551/
- https://www.exploit-db.com/exploits/38905/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-5603