-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability involves path traversal leading to information disclosure via stack traces. Hawtio's ResourceServlet handles static resource requests and would be the logical location for path processing. The lack of path normalization/sanitization in the vulnerable version would allow '../' sequences to access unauthorized paths. When the resolved path doesn't exist, a NullPointerException occurs during resource handling, leaking stack traces. The function signature matches the expected resource handling mechanism described in advisories, and the CWE-22 classification confirms path traversal context.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| io.hawt:project | maven | < 1.5.0 | 1.5.0 |
Ongoing coverage of React2Shell