ZeroHour

CVE-2017-2589

CVSS 3.0
9.0 critical
EPSS
<1%p58
Published
()
Modified
Description

It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.

Vendors
hawtredhat
Products
hawtio, jboss fuse
Weakness
CWE-285
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.