High severity8.8NVD Advisory· Published Dec 29, 2017· Updated May 13, 2026
CVE-2014-0120
CVE-2014-0120
Description
Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated by running "shutdown -f."
Affected products
2- cpe:2.3:a:redhat:jboss_fuse:6.1.0:beta:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- github.com/hawtio/hawtio/commit/b4e23e002639c274a2f687ada980118512f06113nvdIssue TrackingPatchThird Party Advisory
- infocon.org/cons/SyScan/SyScan%202015%20Singapore/SyScan%202015%20Singapore%20presentations/SyScan15%20David%20Jorm%20-%20Finding%20and%20exploiting%20novel%20flaws%20in%20Java%20software.pdfnvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.