Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m4j5-hgqq-5jf2

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9

Описание

Insecure cookie sharing in Hawtio

It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.

Пакеты

Наименование

io.hawt:project

maven
Затронутые версииВерсия исправления

< 1.5.0

1.5.0

EPSS

Процентиль: 39%
0.00175
Низкий

9 Critical

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 8.7
redhat
больше 8 лет назад

It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.

CVSS3: 8.7
nvd
больше 7 лет назад

It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.

EPSS

Процентиль: 39%
0.00175
Низкий

9 Critical

CVSS3

Дефекты

CWE-200