CVE-2017-2589

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-2589
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-2589.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-2589
Aliases
Published
2018-07-26T15:29:00Z
Modified
2024-09-03T01:49:37.878343Z
Severity
  • 9.0 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.

References

Affected packages

Git / github.com/hawtio/hawtio

Affected ranges

Type
GIT
Repo
https://github.com/hawtio/hawtio
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

hawtio-1.*

hawtio-1.0
hawtio-1.1-SNAPSHOT
hawtio-1.2-M10
hawtio-1.2-M11
hawtio-1.2-M12
hawtio-1.2-M13
hawtio-1.2-M14
hawtio-1.2-M15
hawtio-1.2-M16
hawtio-1.2-M17
hawtio-1.2-M18
hawtio-1.2-M19
hawtio-1.2-M2
hawtio-1.2-M20
hawtio-1.2-M21
hawtio-1.2-M22
hawtio-1.2-M23
hawtio-1.2-M24
hawtio-1.2-M25
hawtio-1.2-M26
hawtio-1.2-M27
hawtio-1.2-M3
hawtio-1.2-M4
hawtio-1.2-M5
hawtio-1.2-M6
hawtio-1.2-M7
hawtio-1.2-M8
hawtio-1.2-M9
hawtio-1.2-SNAPSHOT
hawtio-1.2.0
hawtio-1.2.1
hawtio-1.2.2
hawtio-1.2.3
hawtio-1.3.0
hawtio-1.3.1
hawtio-1.4.0

v0.*

v0.1