CVE-2017-8058

Description

Acceptance of invalid/self-signed TLS certificates in Atlassian HipChat before 3.16.2 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept information sent during the login API call.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.115

Associated Vulnerability

VulnerabilityOS Platform
update hipchat 3.16.1 to latest versionWindows
update hipchat 3.16.1 to latest version (For Ubuntu)Linux
update hipchat 3.16.1 to latest version (For Debian)Linux
update hipchat 3.16.1 to latest version (For Centos)Linux
update hipchat 3.16.1 to latest version (For RedHat)Linux
update hipchat 3.16.1 to latest version (For Suse)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234