{"id":"CVE-2017-7556","aliases":["GHSA-q4q2-fvwf-6ghv"],"url":"https://o3.security/vulnerability/CVE-2017-7556","summary":"Cross-Site Request Forgery in hawtio","details":"Hawtio versions up to and including 1.5.3 are vulnerable to CSRF vulnerability allowing remote attackers to trick the user to visit their website containing a malicious script which can be submitted to hawtio server on behalf of the user.","published":"2017-08-17T19:29:00.270Z","modified":"2026-07-08T16:53:37.674384Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":{"score":0.00683,"percentile":0.49528,"asOf":"2026-08-18"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"io.hawt:project","fixedVersion":"1.5.4"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/100411"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1480060"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T16:53:37.674384Z"}}