Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3pgx-46rx-xc9j

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file which could be executed on a target machine where hawtio is deployed.

hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file which could be executed on a target machine where hawtio is deployed.

EPSS

Процентиль: 72%
0.007
Низкий

7.8 High

CVSS3

Дефекты

CWE-20
CWE-434

Связанные уязвимости

CVSS3: 7.6
redhat
около 9 лет назад

hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file which could be executed on a target machine where hawtio is deployed.

CVSS3: 7.6
nvd
больше 7 лет назад

hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file which could be executed on a target machine where hawtio is deployed.

EPSS

Процентиль: 72%
0.007
Низкий

7.8 High

CVSS3

Дефекты

CWE-20
CWE-434