PT-2018-7123 · Hawtio · Hawtio

Publicado

2018-05-08

·

Atualizado

2022-05-13

·

CVE-2017-2594

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: hawtio versions prior to 2.0-beta-1 hawtio versions prior to 2.0-beta-2 hawtio versions prior to 2.0-m1 hawtio versions prior to 2.0-m2 hawtio versions prior to 2.0-m3 hawtio version 1.5
Description: The issue allows an attacker to gather undisclosed information from within hawtio's root due to a path traversal flaw that leads to a NullPointerException with a full stacktrace.
Recommendations: For versions prior to 2.0-beta-1, update to version 2.0-beta-1 or later. For versions prior to 2.0-beta-2, update to version 2.0-beta-2 or later. For versions prior to 2.0-m1, update to version 2.0-m1 or later. For versions prior to 2.0-m2, update to version 2.0-m2 or later. For versions prior to 2.0-m3, update to version 2.0-m3 or later. For version 1.5, update to a version later than 1.5.

Correção

Path traversal

Generation of Error Message Containing Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-2594
GHSA-9G8W-PJPR-PRR4

Produtos afetados

Hawtio