CVE-2016-6668: Infoleak
The Atlassian Hipchat Integration Plugin for Bitbucket Server 6.26.0 before 6.27.5, 6.28.0 before 7.3.7, and 7.4.0 before 7.8.17; Confluence HipChat plugin 6.26.0 before 7.8.17; and HipChat for JIRA plugin 6.26.0 before 7.8.17 allows remote attackers to obtain the secret key for communicating with HipChat instances by reading unspecified pages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6668?
CVE-2016-6668 has been rated as a medium severity vulnerability due to its potential to allow unauthorized access to sensitive information.
How do I fix CVE-2016-6668?
To fix CVE-2016-6668, you should update the vulnerable Atlassian Hipchat Integration Plugin to versions 6.27.5 or higher, or the respective plugin versions in Confluence and JIRA listed in the advisory.
What systems are affected by CVE-2016-6668?
CVE-2016-6668 affects various versions of the Atlassian Hipchat Integration Plugin for Bitbucket Server, Confluence HipChat plugin, and HipChat for JIRA.
What type of attack does CVE-2016-6668 enable?
CVE-2016-6668 allows remote attackers to potentially obtain the secret key used for communications with HipChat, leading to unauthorized access.
Is there a patch available for CVE-2016-6668?
Yes, a patch is available by upgrading to the latest versions of the affected plugins as indicated in the vulnerability advisory.