CVE-2014-0121Improper Authentication in Hawtio

Severity
9.8CRITICALNVD
EPSS
1.5%
top 18.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 29
Latest updateMay 14

Description

The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDhawt/hawtio1.2.2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vj5p-v2jp-m9w5: The admin terminal in Hawt2022-05-14
CVEList
CVE-2014-0121: The admin terminal in Hawt2017-12-29

💬Community

1
Bugzilla
CVE-2014-0121 hawtio-karaf-terminal: remote code execution due to missing authentication2014-03-05