Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

HipChat patch for CVE-2018-11776?

Rob Crowell August 24, 2018

Do we have any hope of getting a patch for this?

https://cwiki.apache.org/confluence/display/WW/S2-057

1 answer

0 votes
AhmadDanial
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
August 27, 2018

Hi there, Rob.

We've been reviewing the CVE in depth and can report back that HipChat and Embedded Crowd are not affected. The vulnerability relies on certain namespace mappings being set to 'true' whereas we've explicitly set our namespaces in the code as required, and this value by default is set to 'false' when not defined. 

At present, most security scanners may just pick this CVE up due to the struts library version, however, this should be marked as a false positive for now. We will be issuing updates to Crowd and HipChat with version bumps to correct this as soon as we can. 

You can watch our HipChat Server Release Notes page for new updates when they are released. Hope that helps!

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events