hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file which could be executed on a target machine where hawtio is deployed.
2018-05-22T17:29:00.407
2025-08-05T14:35:48.620
Analyzed
CVSSv3.0: 7.6 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4