← Vulnerability feed

Vulnerability record · CVE-2015-5603 · published 21 September 2015

CVE-2015-5603: HipChat for JIRA plugin Velocity template injection enables Java code execution

Atlassian · Hipchat

The HipChat for JIRA plugin before 6.30.0 fails to properly handle Velocity template input, allowing remote authenticated users to inject template directives that execute arbitrary Java code. Because the plugin runs inside JIRA, successful exploitation compromises the JIRA server itself, not just the chat integration.

6.5 CVSS 2.0 Medium EPSS 59% · top 0.9% CWE-94 · Code injection
6.5CVSS 2.0 base score
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecified vectors, related to "Velocity Template Injection Vulnerability."

AV:N/AC:L/Au:S/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityPublic exploit code and a very high EPSS score make exploitation likely, though the requirement for authentication and the dated plugin version temper the rating below critical.

What it is

The HipChat for JIRA plugin before 6.30.0 fails to properly handle Velocity template input, allowing remote authenticated users to inject template directives that execute arbitrary Java code. Because the plugin runs inside JIRA, successful exploitation compromises the JIRA server itself, not just the chat integration.

Impact

An attacker gains arbitrary Java code execution in the context of the JIRA server process, enabling data theft, lateral movement, or full host compromise. The CVSS 2.0 vector rates partial confidentiality, integrity and availability impact.

Attack surface

Reachable over the network (AV:N) with low attack complexity (AC:L), but it requires a valid authenticated account (Au:S). No user interaction is indicated by the vector; the flaw is triggered through the plugin's Velocity template handling.

Exploitation

Not listed in CISA KEV, but public exploit code exists (Exploit-DB 38551 and 38905, Rapid7 Metasploit module) and EPSS is 0.59312 (99th percentile), indicating high likelihood of attempted exploitation.

What to do

  • Upgrade the HipChat for JIRA plugin to version 6.30.0 or later as the primary fix.
  • If immediate upgrade is not possible, disable or remove the HipChat for JIRA plugin until patched.
  • Restrict JIRA account creation and review existing accounts for unnecessary privileges, since exploitation requires authentication.
  • Monitor the vendor advisory (Atlassian security advisory 2015-08-26) for any additional guidance.
  • Apply network segmentation so the JIRA server cannot reach untrusted internal services if compromised.

Detection

  • Search JIRA and application logs for Velocity template syntax or unusual template-related errors originating from the HipChat plugin.
  • Monitor for unexpected child processes or outbound connections spawned by the JIRA Java process.
  • Review JIRA audit logs for anomalous authenticated user activity around the HipChat plugin endpoints.
  • Use the public Exploit-DB and Metasploit module signatures to build IDS/IPS rules for known exploit traffic.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-5603 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-14586Atlassian hipchat memory buffer overflow vulnerabilityThe Hipchat for Mac desktop client is vulnerable to client-side remote code execution via video call link parsing. Hipchat for Mac desktop clients at…EPSS 3.5%8.8CVE-2018-1000418Atlassian hipchat incorrect authorization vulnerabilityAn improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall…EPSS 1.1%6.5CVE-2018-1000419Atlassian hipchat vulnerabilityAn improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall…EPSS 1.6%5.9CVE-2017-8058Atlassian hipchat improper certificate validation vulnerabilityAcceptance of invalid/self-signed TLS certificates in Atlassian HipChat before 3.16.2 for iOS allows a man-in-the-middle and/or physically proximate …EPSS 0.58%8.8CVE-2026-65660Microsoft sharepoint server code injection vulnerabilityImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.KEVEPSS 2.1%9.8CVE-2026-60004Gitea diffpatch API code injection enables remote code executionGitea before 1.27.1 allows remote code execution through the diffpatch API by way of Git hook installation. The flaw is a code injection issue (CWE-9…KEVEPSS 24%analysed9.5CVE-2026-72530TrueConf Server sandbox breakout via crafted script code injectionTrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5 and earlier allow a remote unauthenticated attacker to break o…KEVEPSS 1.7%analysed9.4CVE-2025-62593Ray browser-based RCE via insufficient User-Agent guardRay, an AI compute engine, contains a critical remote code execution flaw before version 2.52.0. Its defense against browser-based attacks relies on …KEVEPSS 62%analysed

Source: NIST National Vulnerability Database (record CVE-2015-5603), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.