Vulnerabilities
Vulnerable Software
Hawt:  >> Hawtio  >> 1.3.1  Security Vulnerabilities
Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substring of a URI.
CVSS Score
9.8
EPSS Score
0.046
Published
2019-07-03
hawtio before versions 2.0-beta-1, 2.0-beta-2 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 is vulnerable to a path traversal that leads to a NullPointerException with a full stacktrace. An attacker could use this flaw to gather undisclosed information from within hawtio's root.
CVSS Score
5.4
EPSS Score
0.021
Published
2018-05-08


Contact Us

Shodan ® - All rights reserved