Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-12397

Опубликовано: 10 дек. 2024
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.

Отчет

Red Hat has evaluated this vulnerability. This is a very similar vulnerability to an Undertow, seen in CVE-2023-4639.

Меры по смягчению последствий

Currently, no mitigation is available for this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 3quarkus-http-coreAffected
Red Hat build of Apache Camel 4 for Quarkus 3quarkus-camel-bomAffected
Red Hat build of Apache Camel 4 for Quarkus 3quarkus-cxf-bomAffected
Red Hat build of Apicurio Registry 2quarkus-http-coreAffected
Red Hat Build of Keycloakquarkus-http-coreAffected
Red Hat build of OptaPlanner 8quarkus-http-coreWill not fix
Red Hat Fuse 7quarkus-http-coreOut of support scope
Red Hat Integration Camel K 1quarkus-http-coreAffected
Red Hat JBoss Enterprise Application Platform 8quarkus-http-coreNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packquarkus-http-coreNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=2331298io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling

EPSS

Процентиль: 54%
0.00796
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
nvd
больше 1 года назад

A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.

CVSS3: 7.4
github
больше 1 года назад

io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling

EPSS

Процентиль: 54%
0.00796
Низкий

7.4 High

CVSS3