First published: Thu Aug 10 2017(Updated: )
It was found that hawtio contains a CSRF flaw that allows unrelated websites to perform actions as the authenticated in user. Attacker could use this vulnerability to trick the user to visit his website that contains a malicious script which can be submitted to hawtio server on behalf of the user.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hawt Hawtio | =1.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.