Red Hat Bugzilla – Bug 1419363
CVE-2017-2617 Hawtio: Unrestricted file upload leads to RCE
Last modified: 2018-06-29 18:18:33 EDT
It was found that a flaw in hawtio could cause remote code execution via file upload. An attacker could use this vulnerability to upload crafted file which could be executed on target machine where hawtio is deployed.
Acknowledgments: Name: Hooman Broujerdi (Red Hat)
This issue has been addressed in the following products: Red Hat JBoss Fuse Via RHSA-2018:0319 https://access.redhat.com/errata/RHSA-2018:0319