Vulnerability record · CVE-2015-5603 · published 21 September 2015
CVE-2015-5603: HipChat for JIRA plugin Velocity template injection enables Java code execution
Atlassian · Hipchat
The HipChat for JIRA plugin before 6.30.0 fails to properly handle Velocity template input, allowing remote authenticated users to inject template directives that execute arbitrary Java code. Because the plugin runs inside JIRA, successful exploitation compromises the JIRA server itself, not just the chat integration.
Description
The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecified vectors, related to "Velocity Template Injection Vulnerability."
AV:N/AC:L/Au:S/C:P/I:P/A:P
Automated analysis
high priorityPublic exploit code and a very high EPSS score make exploitation likely, though the requirement for authentication and the dated plugin version temper the rating below critical.
What it is
The HipChat for JIRA plugin before 6.30.0 fails to properly handle Velocity template input, allowing remote authenticated users to inject template directives that execute arbitrary Java code. Because the plugin runs inside JIRA, successful exploitation compromises the JIRA server itself, not just the chat integration.
Impact
An attacker gains arbitrary Java code execution in the context of the JIRA server process, enabling data theft, lateral movement, or full host compromise. The CVSS 2.0 vector rates partial confidentiality, integrity and availability impact.
Attack surface
Reachable over the network (AV:N) with low attack complexity (AC:L), but it requires a valid authenticated account (Au:S). No user interaction is indicated by the vector; the flaw is triggered through the plugin's Velocity template handling.
Exploitation
Not listed in CISA KEV, but public exploit code exists (Exploit-DB 38551 and 38905, Rapid7 Metasploit module) and EPSS is 0.59312 (99th percentile), indicating high likelihood of attempted exploitation.
What to do
- Upgrade the HipChat for JIRA plugin to version 6.30.0 or later as the primary fix.
- If immediate upgrade is not possible, disable or remove the HipChat for JIRA plugin until patched.
- Restrict JIRA account creation and review existing accounts for unnecessary privileges, since exploitation requires authentication.
- Monitor the vendor advisory (Atlassian security advisory 2015-08-26) for any additional guidance.
- Apply network segmentation so the JIRA server cannot reach untrusted internal services if compromised.
Detection
- Search JIRA and application logs for Velocity template syntax or unusual template-related errors originating from the HipChat plugin.
- Monitor for unexpected child processes or outbound connections spawned by the JIRA Java process.
- Review JIRA audit logs for anomalous authenticated user activity around the HipChat plugin endpoints.
- Use the public Exploit-DB and Metasploit module signatures to build IDS/IPS rules for known exploit traffic.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-5603 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-5603), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.