It is supposed to be logged in to navigate inside Hawtio page. However, it is possible to specify a direct URL link (for example: "http://localhost:8181/hawtio/osgi") to somewhere and it will pass you without authentication.
It will not show and load any sensitive information but still it does not look OK.
- relates to
-
ENTESB-10468 [Hawtio] Direct url gives an access to Hawtio without authentication
- Closed
-
ENTESB-10823 [Hawtio] Direct url gives an access to Hawtio without authentication [7.3.1]
- Closed
-
ENTESB-10798 [Hawtio] Direct url gives an access to Hawtio without authentication
- Closed