Vulnerability Name: JIRA and HipChat for JIRA Plugin - Velocity Template Injection Vulnerability EDB-ID: 38551 CVE-ID: CVE-2015-5603 Author: Chris Wood Type: WEBAPPS Platform: JAVA Date: 2015-10-28 Affected Application: JIRA and the HipChat for JIRA plugin Affected Versions: - HipChat For JIRA plugin versions: 1.3.2 Test Environment: JIRA 6.3.4a with HipChat 6.29.2 on Windows 7 x64 Vulnerability Description: Allows any authenticated JIRA user to execute code running as the Tomcat identity