Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-7556

Опубликовано: 09 авг. 2017
Источник: redhat
CVSS3: 5.3

Описание

Hawtio versions up to and including 1.5.3 are vulnerable to CSRF vulnerability allowing remote attackers to trick the user to visit their website containing a malicious script which can be submitted to hawtio server on behalf of the user.

It was found that hawtio contains a CSRF flaw that allows unrelated websites to perform actions as the authenticated user. Attackers could use this vulnerability to trick the user to visit his website that contains a malicious script which can be submitted to hawtio server on behalf of the user.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss A-MQ 6hawtioOut of support scope
Red Hat JBoss Fuse 6hawtioOut of support scope
Red Hat JBoss Fuse Service Works 6hawtioWill not fix
Red Hat OpenShift Enterprise 3hawtioNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-352

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
больше 8 лет назад

Hawtio versions up to and including 1.5.3 are vulnerable to CSRF vulnerability allowing remote attackers to trick the user to visit their website containing a malicious script which can be submitted to hawtio server on behalf of the user.

CVSS3: 8.8
github
больше 3 лет назад

Cross-Site Request Forgery in hawtio

5.3 Medium

CVSS3