Insecure cookie sharing in Hawtio
Critical severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2023
Description
Published by the National Vulnerability Database
Jul 26, 2018
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Nov 4, 2022
Last updated
Feb 2, 2023
It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.
References