CRITICAL
hawtio: server side request forgery via initial /proxy/ substring of a URI
Published Jul 3, 2019
9.8
CRITICALCVSS 3.0
EPSS 26.80%
Description
Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substring of a URI.
Affected products
No data.
No data.
Red Hat AMQ
n/a
Fixed · RHSA-2020:4154
Red Hat AMQ
n/a
Fixed · RHSA-2020:5365
Red Hat Fuse 6.3
hawtio
Fixed · RHSA-2020:3587
Red Hat Fuse 7.7.0
hawtio
Fixed · RHSA-2020:3192
Red Hat AMQ Broker 7
hawtio
Affected
Red Hat JBoss A-MQ 6
hawtio
Out of support scope
Red Hat JBoss Fuse 6
hawtio
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat AMQ | n/a | Fixed | RHSA-2020:4154 |
| Red Hat AMQ | n/a | Fixed | RHSA-2020:5365 |
| Red Hat Fuse 6.3 | hawtio | Fixed | RHSA-2020:3587 |
| Red Hat Fuse 7.7.0 | hawtio | Fixed | RHSA-2020:3192 |
| Red Hat AMQ Broker 7 | hawtio | Affected | n/a |
| Red Hat JBoss A-MQ 6 | hawtio | Out of support scope | n/a |
| Red Hat JBoss Fuse 6 | hawtio | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://access.redhat.com/security/cve/CVE-2019-9827 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1728604 Issue Tracking
- https://github.com/advisories/GHSA-mcg9-64cp-xwp7 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-9827
- https://www.ciphertechs.com/hawtio-advisory/ x_refsource_MISCExploitThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-9827
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-9827 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1728604 | Issue Tracking | |
| https://github.com/advisories/GHSA-mcg9-64cp-xwp7 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-9827 | ||
| https://www.ciphertechs.com/hawtio-advisory/ | x_refsource_MISCExploitThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-9827 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 3, 2019
Updated Aug 4, 2024
Reserved Mar 14, 2019
Link CVE-2019-9827
CISA Vulnrichment
GHSA-MCG9-64CP-XWP7 Updated n/a