Vulnerabilities > CVE-2019-9827 - Server-Side Request Forgery (SSRF) vulnerability in Hawt Hawtio

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
hawt
CWE-918
critical

Summary

Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substring of a URI.

Vulnerable Configurations

Part Description Count
Application
Hawt
98

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/153524/ciphertechs-hawtio.txt
idPACKETSTORM:153524
last seen2019-07-05
published2019-07-03
reporterCipherTechs
sourcehttps://packetstormsecurity.com/files/153524/Hawtio-2.5.0-Server-Side-Request-Forgery.html
titleHawtio 2.5.0 Server Side Request Forgery