Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3jrv-jgp8-45v3

Опубликовано: 17 нояб. 2024
Источник: github
Github: Прошло ревью
CVSS3: 7.4

Описание

Undertow incorrectly parses cookies

A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.

Пакеты

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

>= 2.3.0.Alpha1, < 2.3.11.Final

2.3.11.Final

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

< 2.2.30.Final

2.2.30.Final

EPSS

Процентиль: 90%
0.05363
Низкий

7.4 High

CVSS3

Дефекты

CWE-444

Связанные уязвимости

CVSS3: 7.4
ubuntu
около 1 года назад

A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.

CVSS3: 7.4
redhat
почти 2 года назад

A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.

CVSS3: 7.4
nvd
около 1 года назад

A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.

CVSS3: 7.4
debian
около 1 года назад

A flaw was found in Undertow, which incorrectly parses cookies with ce ...

CVSS3: 7.4
fstec
около 3 лет назад

Уязвимость веб-сервера Undertow, связанная с недостатками обработки входящих HTTP-запросов, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

EPSS

Процентиль: 90%
0.05363
Низкий

7.4 High

CVSS3

Дефекты

CWE-444