Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated by running "shutdown -f."
hawtio-karaf-terminal does not apply any authentication or authorization constraints by default. A remote attacker could use this flaw to run commands in the Karaf terminal, and therefore execute arbitrary code in the context of the Karaf server process.