VDB

RHSA-2018%3A2840

RHSA-2018%3A2840 PUBLISHED

It was found that Hawtio console does not set HTTPOnly or Secure attributes on cookies. An attacker could use this flaw to rerieve an authenticated user's SessionID, and possibly conduct further attacks with the permissions of the authenticated user.

Affected Products

VendorProductVersions
Red HatRed Hat JBoss Fuse 6.3
Red HatRed Hat JBoss A-MQ 6.3

Timeline

  • Oct 1, 2018 CVE Published
  • Jan 28, 2026 CVE Updated
  • Apr 30, 2026 Distribution Patch
  • Apr 30, 2026 Distribution Patch
  • Apr 30, 2026 Security Advisory
  • Apr 30, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›