CVE-2017-8080: Malicious File Upload
Published May 5, 2017
·Updated
Atlassian Hipchat Server before 2.2.4 allows remote authenticated users with user level privileges to execute arbitrary code via vectors involving image uploads.
Affected Software
1 affected component
Atlassian Hipchat Server<=2.2.3
Remediation
Patch Available
Event History
May 5, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8080?
CVE-2017-8080 is a critical vulnerability that allows remote authenticated users to execute arbitrary code on Atlassian Hipchat Server.
2
How do I fix CVE-2017-8080?
To fix CVE-2017-8080, upgrade to Atlassian Hipchat Server version 2.2.4 or later.
3
Who is affected by CVE-2017-8080?
CVE-2017-8080 affects remote authenticated users with user level privileges on Atlassian Hipchat Server versions up to 2.2.3.
4
What kind of attack does CVE-2017-8080 enable?
CVE-2017-8080 enables an attacker to execute arbitrary code via manipulated image uploads.
5
When was CVE-2017-8080 disclosed?
CVE-2017-8080 was disclosed on April 24, 2017.