CVE-2023-33544: Path Traversal
hawtio 2.17.2 is vulnerable to Path Traversal. it is possible to input malicious zip files, which can result in the high-risk files after decompression being stored in any location, even leading to file overwrite.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33544?
CVE-2023-33544 is considered a high-risk vulnerability due to its potential for file overwrite through path traversal.
How do I fix CVE-2023-33544?
To fix CVE-2023-33544, update to a patched version of Hawtio that addresses the path traversal vulnerability.
What software is affected by CVE-2023-33544?
CVE-2023-33544 specifically affects Hawtio version 2.17.2 and Maven package io.hawt:project up to version 2.17.2.
What kind of attacks can CVE-2023-33544 facilitate?
CVE-2023-33544 can facilitate attacks that exploit path traversal to store malicious files in unintended locations.
Can CVE-2023-33544 lead to data loss?
Yes, CVE-2023-33544 can lead to data loss as it allows for the overwriting of critical files during the extraction of malicious zip files.