CVE-2017-2594: Hawt Hawtio
High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.
hawtio before versions 2.0-beta-1, 2.0-beta-2 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 is vulnerable to a path traversal that leads to a NullPointerException with a full stacktrace. An attacker could use this flaw to gather undisclosed information from within hawtio's root.
Affected products
- Hawt Hawtio: up to and including 1.4.68
Published 2018-05-08. Last modified 2026-06-17.