CVE-2017-2589

It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hawt:hawtio:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_fuse:6.3:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-07-26 15:29

Updated : 2023-12-10 12:44


NVD link : CVE-2017-2589

Mitre link : CVE-2017-2589

CVE.ORG link : CVE-2017-2589


JSON object : View

Products Affected

hawt

  • hawtio

redhat

  • jboss_fuse
CWE
NVD-CWE-noinfo CWE-285

Improper Authorization