Описание
A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Migration Toolkit for Applications 6 | org.keycloak-keycloak-parent | Not affected | ||
| Red Hat build of Apache Camel for Spring Boot 3 | undertow | Not affected | ||
| Red Hat build of Apicurio Registry 2 | undertow | Under investigation | ||
| Red Hat build of Debezium 1 | undertow | Under investigation | ||
| Red Hat build of Quarkus | io.quarkus/quarkus-undertow | Under investigation | ||
| Red Hat Data Grid 8 | undertow | Not affected | ||
| Red Hat Decision Manager 7 | undertow | Under investigation | ||
| Red Hat Fuse 7 | undertow | Under investigation | ||
| Red Hat Integration Camel K 1 | undertow | Not affected | ||
| Red Hat Integration Camel Quarkus 1 | undertow | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.4 High
CVSS3
Связанные уязвимости
A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.
A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.
A flaw was found in Undertow, which incorrectly parses cookies with ce ...
Уязвимость веб-сервера Undertow, связанная с недостатками обработки входящих HTTP-запросов, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации
EPSS
7.4 High
CVSS3