Vulnerability record · CVE-2017-2589 · published 26 July 2018
CVE-2017-2589: Hawtio improper authorization vulnerability
Hawt · Hawtio
It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.
Description
It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://access.redhat.com/errata/RHSA-2017:1832 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2589 | Issue TrackingVendor Advisory |
| https://access.redhat.com/errata/RHSA-2017:1832 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2589 | Issue TrackingVendor Advisory |
Track CVE-2017-2589 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-2589), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.