PT-2018-7123 · Hawtio · Hawtio

Published

2018-05-08

·

Updated

2022-05-13

·

CVE-2017-2594

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: hawtio versions prior to 2.0-beta-1 hawtio versions prior to 2.0-beta-2 hawtio versions prior to 2.0-m1 hawtio versions prior to 2.0-m2 hawtio versions prior to 2.0-m3 hawtio version 1.5
Description: The issue allows an attacker to gather undisclosed information from within hawtio's root due to a path traversal flaw that leads to a NullPointerException with a full stacktrace.
Recommendations: For versions prior to 2.0-beta-1, update to version 2.0-beta-1 or later. For versions prior to 2.0-beta-2, update to version 2.0-beta-2 or later. For versions prior to 2.0-m1, update to version 2.0-m1 or later. For versions prior to 2.0-m2, update to version 2.0-m2 or later. For versions prior to 2.0-m3, update to version 2.0-m3 or later. For version 1.5, update to a version later than 1.5.

Fix

Path traversal

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-2594
GHSA-9G8W-PJPR-PRR4

Affected Products

Hawtio