CVE-2017-7357: Malicious File Upload
Published Apr 14, 2017
·Updated
Hipchat Server before 2.2.3 allows remote authenticated users with Server Administrator level privileges to execute arbitrary code by importing a file.
Affected Software
1 affected component
Atlassian Hipchat Server<=2.2.2
Remediation
Patch Available
Event History
Apr 14, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7357?
CVE-2017-7357 is rated as critical due to the potential for remote code execution by authenticated users.
2
How do I fix CVE-2017-7357?
To mitigate CVE-2017-7357, upgrade Hipchat Server to version 2.2.3 or later.
3
Who is affected by CVE-2017-7357?
CVE-2017-7357 affects Hipchat Server versions prior to 2.2.3.
4
What type of attack does CVE-2017-7357 represent?
CVE-2017-7357 represents a remote code execution vulnerability that can be exploited by authenticated users.
5
What privileges are needed to exploit CVE-2017-7357?
To exploit CVE-2017-7357, a user must have Server Administrator level privileges.