GHSA-m4j5-hgqq-5jf2
CRITICALCVE-2017-2589It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.
- Affected
- < 1.5.0
- Fixed in
- 1.5.0
- Weakness
- CWE-200
- Published
- 2022-05-13
- Source
- github