[MAVEN:GHSA-9G8W-PJPR-PRR4] Path Traversal in io.hawt:project

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

hawtio before versions 2.0-beta-1, 2.0-beta-2, 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 are vulnerable to a path traversal that leads to a NullPointerException with a full stacktrace. An attacker could use this flaw to gather undisclosed information from within hawtio's root.

Package Affected Version
pkg:maven/io.hawt/project < 1.5.0
Package Fixed Version
pkg:maven/io.hawt/project = 1.5.0
ID
MAVEN:GHSA-9G8W-PJPR-PRR4
Severity
high
URL
https://github.com/advisories/GHSA-9g8w-pjpr-prr4
Published
2022-05-13T01:36:55
(2 years ago)
Modified
2023-02-02T05:01:23
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/io.hawt/project io.hawt project < 1.5.0
Fixed pkg:maven/io.hawt/project io.hawt project = 1.5.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...