CVE-2017-2589

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/07/2018
Last modified:
09/10/2019

Description

It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hawt:hawtio:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_fuse:6.3:*:*:*:*:*:*:*