VDB
RHSA-2020%3A3587
RHSA-2020%3A3587
PUBLISHED
CVSS 5.5 MEDIUM
Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substring of a URI.
Risk Scores
CVSS 3.0
5.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Fuse 6.3 |
Timeline
- Sep 1, 2020 CVE Published
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 14, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2020:3587 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=jboss.amq.broker&downloadType=securityPatches&version=6.3.0 advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=jboss.fuse&downloadType=securityPatches&version=6.3 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1728604 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1767483 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1855786 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_3587.json advisory
- https://access.redhat.com/security/cve/CVE-2019-9827 advisory
- https://www.cve.org/CVERecord?id=CVE-2019-9827 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-9827 advisory
- https://access.redhat.com/security/cve/CVE-2019-10086 advisory
- https://www.cve.org/CVERecord?id=CVE-2019-10086 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10086 advisory
- https://commons.apache.org/proper/commons-beanutils/javadocs/v1.9.4/RELEASE-NOTES.txt advisory
- https://access.redhat.com/security/cve/CVE-2020-11994 advisory
- https://www.cve.org/CVERecord?id=CVE-2020-11994 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-11994 advisory