← Back

CVE-2014-0120

nvd nist
Published: Dec 29, 2017Modified: May 13, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated by running "shutdown -f."

Affected (2)

Products: Hawt: Hawtio · Redhat: Jboss Fuse
1 product
Hawtio
1 product
Jboss Fuse
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.2.2
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.1.0 beta

References (6)

Timeline

No history available yet.