Описание
hawtio 2.17.2 is vulnerable to Path Traversal. it is possible to input malicious zip files, which can result in the high-risk files after decompression being stored in any location, even leading to file overwrite.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat AMQ Broker 7 | hawtio | Not affected | ||
| Red Hat Fuse 7 | hawtio | Not affected | ||
| Red Hat JBoss Data Grid 7 | hawtio | Not affected | ||
| Red Hat JBoss Data Virtualization 6 | hawtio | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7 | hawtio | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | hawtio | Not affected | ||
| Red Hat JBoss Fuse 6 | hawtio | Out of support scope | ||
| Red Hat JBoss Fuse Service Works 6 | hawtio | Out of support scope |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2212918hawtio: path traversal via unsafe zip decompression
EPSS
Процентиль: 16%
0.00051
Низкий
5.5 Medium
CVSS3
Связанные уязвимости
CVSS3: 5.5
nvd
больше 2 лет назад
hawtio 2.17.2 is vulnerable to Path Traversal. it is possible to input malicious zip files, which can result in the high-risk files after decompression being stored in any location, even leading to file overwrite.
EPSS
Процентиль: 16%
0.00051
Низкий
5.5 Medium
CVSS3