hawtio before versions 2.0-beta-1, 2.0-beta-2 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 is vulnerable to a path traversal that leads to a NullPointerException with a full stacktrace. An attacker could use this flaw to gather undisclosed information from within hawtio's root.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| io.hawt:project(Maven) | 0 | 1.5.0 | N/A |
CVSS Metrics