Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cwp7-v7x9-vx2r

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated by running "shutdown -f."

Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated by running "shutdown -f."

EPSS

Процентиль: 30%
0.00109
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

redhat
почти 12 лет назад

Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated by running "shutdown -f."

CVSS3: 8.8
nvd
около 8 лет назад

Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated by running "shutdown -f."

EPSS

Процентиль: 30%
0.00109
Низкий

8.8 High

CVSS3

Дефекты

CWE-352