PT-2023-24377 · Hawtio · Hawtio

Poppingsnack

·

Publicado

2023-06-01

·

Atualizado

2025-01-09

·

CVE-2023-33544

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions hawtio version 2.17.2
Description The issue allows an attacker to input malicious zip files, which can result in high-risk files after decompression being stored in any location, potentially leading to file overwrite. This is due to a Path Traversal vulnerability.
Recommendations For hawtio version 2.17.2, consider restricting the input of zip files or implementing validation to prevent malicious files from being decompressed and stored in sensitive locations. As a temporary workaround, avoid using the zip file upload feature until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-33544
GHSA-P223-C4W6-Q454

Produtos afetados

Hawtio