CVE-2017-2589Improper Authorization in RED HAT Hawtio

Severity
9.0CRITICALNVD
CNA8.7
EPSS
0.2%
top 62.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 26
Latest updateMay 13

Description

It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HExploitability: 2.3 | Impact: 6.0

Affected Packages3 packages

NVDhawt/hawtio1.4.0
CVEListV5red_hat/hawtio1.4

🔴Vulnerability Details

3
OSV
Insecure cookie sharing in Hawtio2022-05-13
GHSA
Insecure cookie sharing in Hawtio2022-05-13
CVEList
CVE-2017-2589: It was discovered that the hawtio servlet 12018-07-26

📋Vendor Advisories

1
Red Hat
hawtio: Proxy is sharing cookies among all the clients2017-07-28

💬Community

1
Bugzilla
CVE-2017-2589 hawtio: Proxy is sharing cookies among all the clients2017-01-17
CVE-2017-2589 — Improper Authorization in RED | cvebase