PT-2023-24377 · Hawtio · Hawtio

Poppingsnack

·

Published

2023-06-01

·

Updated

2025-01-09

·

CVE-2023-33544

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions hawtio version 2.17.2
Description The issue allows an attacker to input malicious zip files, which can result in high-risk files after decompression being stored in any location, potentially leading to file overwrite. This is due to a Path Traversal vulnerability.
Recommendations For hawtio version 2.17.2, consider restricting the input of zip files or implementing validation to prevent malicious files from being decompressed and stored in sensitive locations. As a temporary workaround, avoid using the zip file upload feature until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2023-33544
GHSA-P223-C4W6-Q454

Affected Products

Hawtio