VYPR
High severity8.8NVD Advisory· Published Aug 17, 2017· Updated May 13, 2026

CVE-2017-7556

CVE-2017-7556

Description

Hawtio versions up to and including 1.5.3 are vulnerable to CSRF vulnerability allowing remote attackers to trick the user to visit their website containing a malicious script which can be submitted to hawtio server on behalf of the user.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
io.hawt:projectMaven
< 1.5.41.5.4

Affected products

2
  • cpe:2.3:a:hawt:hawtio:1.5.3:*:*:*:*:*:*:*
  • Red Hat, Inc./hawtiov5
    Range: up to and including 1.5.3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.