Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-2594

Опубликовано: 23 янв. 2017
Источник: redhat
CVSS3: 5.4

Описание

hawtio before versions 2.0-beta-1, 2.0-beta-2 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 is vulnerable to a path traversal that leads to a NullPointerException with a full stacktrace. An attacker could use this flaw to gather undisclosed information from within hawtio's root.

It was found that a path traversal vulnerability in hawtio leads to a NullPointerException with a full stacktrace. An attacker could use this flaw to gather undisclosed information from within hawtio's root.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss A-MQ 6hawtioOut of support scope
Red Hat JBoss Fuse 6hawtioOut of support scope
Red Hat OpenShift Enterprise 2hawtioWill not fix
Red Hat JBoss A-MQ 6.3FixedRHSA-2017:183210.08.2017
Red Hat JBoss Fuse 6.3FixedRHSA-2017:183210.08.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-209
https://bugzilla.redhat.com/show_bug.cgi?id=1415543hawtio: information Disclosure flaws due to unsafe path traversal

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
больше 7 лет назад

hawtio before versions 2.0-beta-1, 2.0-beta-2 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 is vulnerable to a path traversal that leads to a NullPointerException with a full stacktrace. An attacker could use this flaw to gather undisclosed information from within hawtio's root.

CVSS3: 7.5
github
больше 3 лет назад

Path Traversal in io.hawt:project

5.4 Medium

CVSS3