Описание
hawtio 2.17.2 is vulnerable to Path Traversal. it is possible to input malicious zip files, which can result in the high-risk files after decompression being stored in any location, even leading to file overwrite.
Ссылки
- ExploitIssue TrackingThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:hawt:hawtio:2.17.2:*:*:*:*:*:*:*
EPSS
Процентиль: 16%
0.00051
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-22
CWE-22
Связанные уязвимости
CVSS3: 5.5
redhat
больше 2 лет назад
hawtio 2.17.2 is vulnerable to Path Traversal. it is possible to input malicious zip files, which can result in the high-risk files after decompression being stored in any location, even leading to file overwrite.
EPSS
Процентиль: 16%
0.00051
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-22
CWE-22