Description
Hawtio versions up to and including 1.5.3 are vulnerable to CSRF vulnerability allowing remote attackers to trick the user to visit their website containing a malicious script which can be submitted to hawtio server on behalf of the user.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1480060
http://www.securityfocus.com/bid/100411
Related Vulnerabilities
CVE-2021-34083 Vulnerability in npm package google-it
CVE-2018-11697 Vulnerability in npm package node-sass
CVE-2019-0199 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2022-29770 Vulnerability in maven package com.xuxueli:xxl-job
CVE-2018-1000863 Vulnerability in maven package org.jenkins-ci.main:jenkins-core