CVE-2017-7556: CSRF
Hawtio versions up to and including 1.5.3 are vulnerable to CSRF vulnerability allowing remote attackers to trick the user to visit their website containing a malicious script which can be submitted to hawtio server on behalf of the user.
Other sources
It was found that hawtio contains a CSRF flaw that allows unrelated websites to perform actions as the authenticated in user. Attacker could use this vulnerability to trick the user to visit his website that contains a malicious script which can be submitted to hawtio server on behalf of the user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7556?
CVE-2017-7556 is classified as a medium severity vulnerability due to its CSRF nature that can lead to unauthorized actions on behalf of authenticated users.
How do I fix CVE-2017-7556?
To mitigate CVE-2017-7556, it is recommended to upgrade to a patched version of Hawtio that addresses the CSRF issue.
What type of vulnerability is CVE-2017-7556?
CVE-2017-7556 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Hawtio management console.
Who is affected by CVE-2017-7556?
CVE-2017-7556 affects users of Hawtio version 1.5.3 who are authenticated and can be exploited by attackers through malicious scripts.
Can CVE-2017-7556 be exploited remotely?
Yes, CVE-2017-7556 can be exploited remotely by tricking users into visiting a malicious website that submits requests to the authenticated session.