CVE-2019-9827
critical · 9.8Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substring of a URI.
9.8
CVSS
26.8%
EPSS (exploit prob.)
98th
EPSS percentile
2019-07-03
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-918
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| hawt | hawtio | <= 2.5.0 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-9827