7.5
CVE-2016-6668
- EPSS 3.71%
- Veröffentlicht 23.01.2017 21:59:02
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The Atlassian Hipchat Integration Plugin for Bitbucket Server 6.26.0 before 6.27.5, 6.28.0 before 7.3.7, and 7.4.0 before 7.8.17; Confluence HipChat plugin 6.26.0 before 7.8.17; and HipChat for JIRA plugin 6.26.0 before 7.8.17 allows remote attackers to obtain the secret key for communicating with HipChat instances by reading unspecified pages.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Atlassian ≫ Confluence Server Version5.5.0
Atlassian ≫ Confluence Server Version5.9.1
Atlassian ≫ Confluence Server Version5.9.2
Atlassian ≫ Confluence Server Version5.9.3
Atlassian ≫ Confluence Server Version5.9.4
Atlassian ≫ Confluence Server Version5.9.5
Atlassian ≫ Confluence Server Version5.9.6
Atlassian ≫ Confluence Server Version5.9.7
Atlassian ≫ Confluence Server Version5.9.8
Atlassian ≫ Confluence Server Version5.9.9
Atlassian ≫ Confluence Server Version5.9.10
Atlassian ≫ Confluence Server Version5.9.11
Atlassian ≫ Confluence Server Version5.9.12
Atlassian ≫ Confluence Server Version5.10.0
Atlassian ≫ Confluence Server Version5.10.1
Atlassian ≫ Confluence Server Version5.10.2
Atlassian ≫ Confluence Server Version5.10.3
Atlassian ≫ Jira Integration For Hipchat Version6.26.0
Atlassian ≫ Jira Integration For Hipchat Version6.26.10
Atlassian ≫ Jira Integration For Hipchat Version6.29.1
Atlassian ≫ Jira Integration For Hipchat Version6.29.2
Atlassian ≫ Jira Integration For Hipchat Version6.31.0
Atlassian ≫ Jira Integration For Hipchat Version7.1.0
Atlassian ≫ Jira Integration For Hipchat Version7.2.1
Atlassian ≫ Jira Integration For Hipchat Version7.3.2
Atlassian ≫ Jira Integration For Hipchat Version7.3.3
Atlassian ≫ Jira Integration For Hipchat Version7.4.1
Atlassian ≫ Jira Integration For Hipchat Version7.8.1
Atlassian ≫ Jira Integration For Hipchat Version7.8.3
Atlassian ≫ Jira Integration For Hipchat Version7.8.12
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.71% | 0.883 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://packetstormsecurity.com/files/139004/Atlassian-HipChat-Secret-Key-Disclosure.html
http://www.securityfocus.com/archive/1/539530/100/0/threaded
http://www.securityfocus.com/bid/93159
https://confluence.atlassian.com/bitbucketserver/bitbucket-server-security-advisory-2016-09-21-840698321.html
https://confluence.atlassian.com/doc/confluence-security-advisory-2016-09-21-849052104.html
https://confluence.atlassian.com/jira/jira-and-hipchat-for-jira-plugin-security-advisory-2016-09-21-849052099.html