CVE-2019-9827: SSRF
Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substring of a URI.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-9827?
CVE-2019-9827 is classified as a potential medium to high severity vulnerability due to its ability to allow SSRF attacks.
How do I fix CVE-2019-9827?
To mitigate CVE-2019-9827, upgrade Hawt Hawtio to version 2.5.1 or later to ensure the vulnerability is patched.
Who is affected by CVE-2019-9827?
CVE-2019-9827 affects all versions of Hawt Hawtio up to and including version 2.5.0.
What type of attack does CVE-2019-9827 enable?
CVE-2019-9827 enables Server-Side Request Forgery (SSRF) attacks, allowing attackers to make HTTP requests from the server.
What should I do if I cannot update to fix CVE-2019-9827?
If you cannot update, consider restricting access to the affected server or implementing network controls to limit potential SSRF exploitation from CVE-2019-9827.