CVE-2017-2589

It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hawt:hawtio:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_fuse:6.3:*:*:*:*:*:*:*

History

21 Nov 2024, 03:23

Type Values Removed Values Added
References () https://access.redhat.com/errata/RHSA-2017:1832 - Vendor Advisory () https://access.redhat.com/errata/RHSA-2017:1832 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2589 - Issue Tracking, Vendor Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2589 - Issue Tracking, Vendor Advisory
CVSS v2 : 6.0
v3 : 9.0
v2 : 6.0
v3 : 8.7

Information

Published : 2018-07-26 15:29

Updated : 2024-11-21 03:23


NVD link : CVE-2017-2589

Mitre link : CVE-2017-2589

CVE.ORG link : CVE-2017-2589


JSON object : View

Products Affected

redhat

  • jboss_fuse

hawt

  • hawtio
CWE
CWE-285

Improper Authorization

NVD-CWE-noinfo