Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2023-33544
Disclosure Date: June 01, 2023 (last updated October 08, 2023)
hawtio 2.17.2 is vulnerable to Path Traversal. it is possible to input malicious zip files, which can result in the high-risk files after decompression being stored in any location, even leading to file overwrite.
0
Attacker Value
Unknown
CVE-2019-9827
Disclosure Date: July 03, 2019 (last updated November 27, 2024)
Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substring of a URI.
0
Attacker Value
Unknown
CVE-2017-2589
Disclosure Date: July 26, 2018 (last updated November 27, 2024)
It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.
0
Attacker Value
Unknown
CVE-2017-2617
Disclosure Date: May 22, 2018 (last updated November 26, 2024)
hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file which could be executed on a target machine where hawtio is deployed.
0
Attacker Value
Unknown
CVE-2017-2594
Disclosure Date: May 08, 2018 (last updated November 26, 2024)
hawtio before versions 2.0-beta-1, 2.0-beta-2 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 is vulnerable to a path traversal that leads to a NullPointerException with a full stacktrace. An attacker could use this flaw to gather undisclosed information from within hawtio's root.
0
Attacker Value
Unknown
CVE-2014-0121
Disclosure Date: December 29, 2017 (last updated November 26, 2024)
The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.
0
Attacker Value
Unknown
CVE-2014-0120
Disclosure Date: December 29, 2017 (last updated November 26, 2024)
Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated by running "shutdown -f."
0
Attacker Value
Unknown
CVE-2017-7556
Disclosure Date: August 17, 2017 (last updated November 26, 2024)
Hawtio versions up to and including 1.5.3 are vulnerable to CSRF vulnerability allowing remote attackers to trick the user to visit their website containing a malicious script which can be submitted to hawtio server on behalf of the user.
0
Attacker Value
Unknown
CVE-2005-4511
Disclosure Date: December 23, 2005 (last updated February 22, 2025)
Format string vulnerability in TN3270 Resource Gateway 1.1.0 allows local users to cause a denial of service and possibly execute arbitrary code via format string specifiers in syslog function calls.
0