Showing 1 vulnerability on this page for hawtio

Signals CISA KEV Ransomware Nuclei
Red Hat, Inc. vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Cross-Site Request Forgery in hawtio

Hawtio versions up to and including 1.5.3 are vulnerable to CSRF vulnerability allowing remote attackers to trick the user to visit their website containing a malicious script which can be submitted to hawtio server on behalf of the user.

CWE-352Aug 17, 2017
CVSS8.8v3.0EPSS0.683%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX