High severity8.7NVD Advisory· Published Jul 26, 2018· Updated Jun 17, 2026
CVE-2017-2589
CVE-2017-2589
Description
It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.hawt:projectMaven | < 1.5.0 | 1.5.0 |
Affected products
2- Red Hat/hawtiov5Range: 1.4
Patches
Vulnerability mechanics
References
5- access.redhat.com/errata/RHSA-2017:1832nvdVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-m4j5-hgqq-5jf2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-2589ghsaADVISORY
- tadayoshi-sato.medium.com/securing-hawtio-f5fbfd5afcf0ghsaWEB
News mentions
0No linked articles in our index yet.