Логотип exploitDog
bind:CVE-2024-12397
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-12397

Количество 3

Количество 3

redhat логотип

CVE-2024-12397

около 1 года назад

A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2024-12397

около 1 года назад

A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-cxrx-q234-m22m

около 1 года назад

io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2024-12397

A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.

CVSS3: 7.4
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-12397

A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.

CVSS3: 7.4
0%
Низкий
около 1 года назад
github логотип
GHSA-cxrx-q234-m22m

io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling

CVSS3: 7.4
0%
Низкий
около 1 года назад

Уязвимостей на страницу