Description
Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated by running "shutdown -f."
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1072681
https://github.com/hawtio/hawtio/commit/b4e23e002639c274a2f687ada980118512f06113
https://infocon.org/cons/SyScan/SyScan%202015%20Singapore/SyScan%202015%20Singapore%20presentations/SyScan15%20David%20Jorm%20-%20Finding%20and%20exploiting%20novel%20flaws%20in%20Java%20software.pdf
Related Vulnerabilities
CVE-2023-31826 Vulnerability in maven package org.skyscreamer:nevado-jms
CVE-2023-40037 Vulnerability in maven package org.apache.nifi:nifi-dbcp-service-api
CVE-2023-37277 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-war
CVE-2022-26969 Vulnerability in npm package directus
CVE-2022-25940 Vulnerability in maven package org.webjars.npm:lite-server