CVE-2017-2617

Related Vulnerabilities: CVE-2017-2617  

It was found that a flaw in hawtio could cause remote code execution via file upload. An attacker could use this vulnerability to upload crafted file which could be executed on a target machine where hawtio is deployed.

It was found that a flaw in hawtio could cause remote code execution via file upload. An attacker could use this vulnerability to upload crafted file which could be executed on a target machine where hawtio is deployed.

Find out more about CVE-2017-2617 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

CVSS3 Base Score 7.6
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity Impact Low
Availability Impact High

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss A-MQ 6.3 RHSA-2018:0319 2018-02-14
Red Hat JBoss Fuse 6.3 RHSA-2018:0319 2018-02-14

Affected Packages State

Platform Package State
Red Hat OpenShift Enterprise 2 hawtio Will not fix

Acknowledgements

This issue was discovered by Hooman Broujerdi (Red Hat).