CVE-2014-0120Cross-Site Request Forgery in Hawtio

Severity
8.8HIGHNVD
EPSS
0.1%
top 70.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 29
Latest updateMay 14

Description

Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated by running "shutdown -f."

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDhawt/hawtio1.2.2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-cwp7-v7x9-vx2r: Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt2022-05-14
CVEList
CVE-2014-0120: Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt2017-12-29

💬Community

1
Bugzilla
CVE-2014-0120 hawtio-karaf-terminal: cross-site request forgery (CSRF)2014-03-05
CVE-2014-0120 — Cross-Site Request Forgery in Hawtio | cvebase