CVE-2017-2589

Source
https://cve.org/CVERecord?id=CVE-2017-2589
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-2589.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-2589
Aliases
Published
2018-07-26T15:29:00.217Z
Modified
2026-07-08T05:49:46.126066182Z
Severity
  • 9.0 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.

Database specific
{
    "unresolved_ranges": [
        {
            "cpes": [
                "cpe:2.3:a:redhat:jboss_fuse:6.3:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "6.3"
                },
                {
                    "last_affected": "6.3"
                }
            ],
            "vendor_product": "redhat:jboss_fuse",
            "source": "CPE_STRING"
        }
    ]
}
References

Affected packages

Git / github.com/hawtio/hawtio

Affected ranges

Type
GIT
Repo
https://github.com/hawtio/hawtio
Events
Database specific
{
    "cpe": "cpe:2.3:a:hawt:hawtio:1.4.0:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.4.0"
        },
        {
            "last_affected": "1.4.0"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

1.*
1.4.0
hawtio-1.*
hawtio-1.4.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-2589.json"