Back

HIGH

Hawtio: Unrestricted file upload leads to RCE

Published May 22, 2018

Description

hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file which could be executed on a target machine where hawtio is deployed.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 22, 2018
Updated Aug 5, 2024
Reserved Dec 1, 2016
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 4, 2017