It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2589 | Issue Tracking Vendor Advisory |
https://access.redhat.com/errata/RHSA-2017:1832 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2018-07-26 08:29
Updated : 2019-10-09 16:26
NVD link : CVE-2017-2589
Mitre link : CVE-2017-2589
JSON object : View
CWE
Products Affected
hawt
- hawtio
redhat
- jboss_fuse