Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-2617

Опубликовано: 04 фев. 2017
Источник: redhat
CVSS3: 7.6
EPSS Низкий

Описание

hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file which could be executed on a target machine where hawtio is deployed.

It was found that a flaw in hawtio could cause remote code execution via file upload. An attacker could use this vulnerability to upload crafted file which could be executed on a target machine where hawtio is deployed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss A-MQ 6hawtioOut of support scope
Red Hat JBoss Fuse 6hawtioOut of support scope
Red Hat OpenShift Enterprise 2hawtioUnder investigation
Red Hat JBoss A-MQ 6.3FixedRHSA-2018:031914.02.2018
Red Hat JBoss Fuse 6.3FixedRHSA-2018:031914.02.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1419363Hawtio: Unrestricted file upload leads to RCE

EPSS

Процентиль: 72%
0.007
Низкий

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 7.6
nvd
больше 7 лет назад

hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file which could be executed on a target machine where hawtio is deployed.

CVSS3: 7.8
github
больше 3 лет назад

hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file which could be executed on a target machine where hawtio is deployed.

EPSS

Процентиль: 72%
0.007
Низкий

7.6 High

CVSS3