Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substring of a URI.
{
"severity": "CRITICAL",
"github_reviewed": true,
"cwe_ids": [
"CWE-918"
],
"nvd_published_at": "2019-07-03T21:15:00Z",
"github_reviewed_at": "2019-07-05T20:47:20Z"
}