CVE-2017-2617

Impact:
Moderate
Public Date:
2017-02-04
CWE:
CWE-20
Bugzilla:
1419363: CVE-2017-2617 Hawtio: Unrestricted file upload leads to RCE
It was found that a flaw in hawtio could cause remote code execution via file upload. An attacker could use this vulnerability to upload crafted file which could be executed on a target machine where hawtio is deployed.

Find out more about CVE-2017-2617 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

CVSS3 Base Score 7.6
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity Impact Low
Availability Impact High

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss A-MQ 6.3 RHSA-2018:0319 2018-02-14
Red Hat JBoss Fuse 6.3 RHSA-2018:0319 2018-02-14

Affected Packages State

Platform Package State
Red Hat OpenShift Enterprise 2 hawtio Will not fix

Acknowledgements

This issue was discovered by Hooman Broujerdi (Red Hat).

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.