First published: Sun Feb 05 2017(Updated: )
hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file which could be executed on a target machine where hawtio is deployed.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/hawtio | <1.5.5 | 1.5.5 |
Red Hat Hawtio | <1.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2617 has a high severity rating due to the potential for remote code execution.
To fix CVE-2017-2617, upgrade hawtio to version 1.5.5 or later.
CVE-2017-2617 affects hawtio versions prior to 1.5.5.
CVE-2017-2617 is classified as a remote code execution vulnerability.
CVE-2017-2617 was reported through security assessments and documented in public security databases.