VDB

CVE-2019-9827

CVE-2019-9827 PUBLISHED CVSS 7.5 HIGH

Reported by mitre · Published July 3, 2019

Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substring of a URI.

Risk Scores

CVSS 2.0
7.5

Affected Products

VendorProductVersions
n/an/an/a
n/an/an/a, n/a, n/a
Mavenio.hawt:hawtio-core0, 0

Timeline

  • Jul 3, 2019 CVE Published
  • Jul 3, 2019 PoC Published
  • Jul 10, 2019 CVE Updated
  • Apr 14, 2021 EPSS Score
  • Aug 25, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Mar 1, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Jul 5, 2022 EPSS Score
  • Nov 8, 2022 EPSS Score
  • Jan 10, 2023 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›