{"id":"GHSA-mcg9-64cp-xwp7","summary":"Server-Side Request Forgery in Hawt Hawtio","details":"Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substring of a URI.","aliases":["CVE-2019-9827"],"modified":"2024-02-16T08:17:46.110595Z","published":"2019-07-05T21:08:09Z","database_specific":{"cwe_ids":["CWE-918"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2019-07-05T20:47:20Z","nvd_published_at":"2019-07-03T21:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-9827"},{"type":"WEB","url":"https://www.ciphertechs.com/hawtio-advisory"}],"affected":[{"package":{"name":"io.hawt:hawtio-core","ecosystem":"Maven","purl":"pkg:maven/io.hawt/hawtio-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.0"}]}],"versions":["1.1","1.2-M1","1.2-M10","1.2-M11","1.2-M13","1.2-M14","1.2-M16","1.2-M19","1.2-M2","1.2-M20","1.2-M22","1.2-M23","1.2-M24","1.2-M25","1.2-M26","1.2-M27","1.2-M3","1.2-M4","1.2-M5","1.2-M6","1.2-M7","1.2-M8","1.2-M9","1.2.0","1.2.1","1.2.2","1.2.3","1.3.0","1.3.1","1.4.0","1.4.1","1.4.10","1.4.11","1.4.12","1.4.14","1.4.15","1.4.16","1.4.17","1.4.18","1.4.19","1.4.2","1.4.20","1.4.21","1.4.22","1.4.23","1.4.24","1.4.25","1.4.26","1.4.27","1.4.28","1.4.29","1.4.30","1.4.31","1.4.32","1.4.33","1.4.34","1.4.35","1.4.36","1.4.37","1.4.38","1.4.39","1.4.4","1.4.40","1.4.41","1.4.42","1.4.43","1.4.44","1.4.45","1.4.46","1.4.47","1.4.48","1.4.49","1.4.5","1.4.50","1.4.51","1.4.52","1.4.53","1.4.54","1.4.55","1.4.56","1.4.57","1.4.58","1.4.59","1.4.6","1.4.60","1.4.61","1.4.62","1.4.63","1.4.64","1.4.65","1.4.66","1.4.67","1.4.68","1.4.7","1.4.8","1.4.9","1.5.0","1.5.1","1.5.10","1.5.11","1.5.12","1.5.2","1.5.3","1.5.4","1.5.5","1.5.6","1.5.7","1.5.8","1.5.9","1.5.X","2.0-M1","2.0-M2","2.0-M3","2.0-beta-1","2.0-beta-2","2.0.0","2.0.1","2.0.2","2.0.3","2.1.0","2.2.0","2.3.0","2.4.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/07/GHSA-mcg9-64cp-xwp7/GHSA-mcg9-64cp-xwp7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}