CVE-2017-2617: Malicious File Upload
hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file which could be executed on a target machine where hawtio is deployed.
Other sources
It was found that a flaw in hawtio could cause remote code execution via file upload. An attacker could use this vulnerability to upload crafted file which could be executed on target machine where hawtio is deployed.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2617?
CVE-2017-2617 has a high severity rating due to the potential for remote code execution.
How do I fix CVE-2017-2617?
To fix CVE-2017-2617, upgrade hawtio to version 1.5.5 or later.
What software is affected by CVE-2017-2617?
CVE-2017-2617 affects hawtio versions prior to 1.5.5.
What type of vulnerability is CVE-2017-2617?
CVE-2017-2617 is classified as a remote code execution vulnerability.
Who discovered CVE-2017-2617?
CVE-2017-2617 was reported through security assessments and documented in public security databases.