It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.
References
Link | Resource |
---|---|
https://access.redhat.com/errata/RHSA-2017:1832 | Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2589 | Issue Tracking Vendor Advisory |
https://access.redhat.com/errata/RHSA-2017:1832 | Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2589 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:23
Type | Values Removed | Values Added |
---|---|---|
References | () https://access.redhat.com/errata/RHSA-2017:1832 - Vendor Advisory | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2589 - Issue Tracking, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : 6.0
v3 : 8.7 |
Information
Published : 2018-07-26 15:29
Updated : 2024-11-21 03:23
NVD link : CVE-2017-2589
Mitre link : CVE-2017-2589
CVE.ORG link : CVE-2017-2589
JSON object : View
Products Affected
redhat
- jboss_fuse
hawt
- hawtio
CWE