CVE-2015-5603: Code Injection
Published Sep 21, 2015
·Updated
The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecified vectors, related to "Velocity Template Injection Vulnerability."
Affected Software
1 affected component
Atlassian HipChat<=6.29.2
Event History
Sep 21, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5603?
CVE-2015-5603 has a high severity due to its potential for remote code execution.
2
How do I fix CVE-2015-5603?
To fix CVE-2015-5603, update the HipChat for JIRA plugin to version 6.30.0 or later.
3
Who is affected by CVE-2015-5603?
CVE-2015-5603 affects users of the HipChat for JIRA plugin prior to version 6.30.0.
4
What type of vulnerability is CVE-2015-5603?
CVE-2015-5603 is identified as a Velocity Template Injection Vulnerability.
5
Can CVE-2015-5603 be exploited remotely?
Yes, CVE-2015-5603 can be exploited by remote authenticated users.