Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p223-c4w6-q454

Опубликовано: 01 июн. 2023
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

hawtio vulnerable to Path Traversal

hawtio 2.17.2 is vulnerable to Path Traversal. it is possible to input malicious zip files, which can result in the high-risk files after decompression being stored in any location, even leading to file overwrite.

Пакеты

Наименование

io.hawt:project

maven
Затронутые версииВерсия исправления

<= 2.17.2

Отсутствует

EPSS

Процентиль: 16%
0.00051
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.5
redhat
больше 2 лет назад

hawtio 2.17.2 is vulnerable to Path Traversal. it is possible to input malicious zip files, which can result in the high-risk files after decompression being stored in any location, even leading to file overwrite.

CVSS3: 5.5
nvd
больше 2 лет назад

hawtio 2.17.2 is vulnerable to Path Traversal. it is possible to input malicious zip files, which can result in the high-risk files after decompression being stored in any location, even leading to file overwrite.

EPSS

Процентиль: 16%
0.00051
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-22