Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-2589

Опубликовано: 28 июл. 2017
Источник: redhat
CVSS3: 8.7
EPSS Низкий

Описание

It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.

It was discovered that the hawtio servlet uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss A-MQ 6hawtioAffected
Red Hat JBoss Fuse 6hawtioAffected
Red Hat OpenShift Enterprise 2hawtioUnder investigation
Red Hat JBoss A-MQ 6.3FixedRHSA-2017:183210.08.2017
Red Hat JBoss Fuse 6.3FixedRHSA-2017:183210.08.2017

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-285
https://bugzilla.redhat.com/show_bug.cgi?id=1413905hawtio: Proxy is sharing cookies among all the clients

EPSS

Процентиль: 39%
0.00175
Низкий

8.7 High

CVSS3

Связанные уязвимости

CVSS3: 8.7
nvd
больше 7 лет назад

It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.

CVSS3: 9
github
больше 3 лет назад

Insecure cookie sharing in Hawtio

EPSS

Процентиль: 39%
0.00175
Низкий

8.7 High

CVSS3