A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with
certain value-delimiting characters in incoming requests. This issue could
allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie
values or spoof arbitrary additional cookie values, leading to unauthorized
data access or modification. The main threat from this flaw impacts data
confidentiality and integrity.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Dec 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 12 Dec 2024 09:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | No description is available for this CVE. | A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity. |
Title | io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling | Io.quarkus.http/quarkus-http-core: quarkus http cookie smuggling |
First Time appeared |
Redhat
Redhat amq Streams Redhat build Keycloak Redhat camel Quarkus Redhat cryostat Redhat integration Redhat jboss Enterprise Application Platform Redhat jboss Enterprise Bpms Platform Redhat jboss Fuse Redhat jbosseapxp Redhat optaplanner Redhat quarkus Redhat rhboac Hawtio Redhat service Registry |
|
CPEs | cpe:/a:redhat:amq_streams:1 cpe:/a:redhat:build_keycloak: cpe:/a:redhat:camel_quarkus:3 cpe:/a:redhat:cryostat:3 cpe:/a:redhat:integration:1 cpe:/a:redhat:jboss_enterprise_application_platform:8 cpe:/a:redhat:jboss_enterprise_bpms_platform:7 cpe:/a:redhat:jboss_fuse:7 cpe:/a:redhat:jbosseapxp cpe:/a:redhat:optaplanner:::el6 cpe:/a:redhat:quarkus:3 cpe:/a:redhat:rhboac_hawtio:4 cpe:/a:redhat:service_registry:2 |
|
Vendors & Products |
Redhat
Redhat amq Streams Redhat build Keycloak Redhat camel Quarkus Redhat cryostat Redhat integration Redhat jboss Enterprise Application Platform Redhat jboss Enterprise Bpms Platform Redhat jboss Fuse Redhat jbosseapxp Redhat optaplanner Redhat quarkus Redhat rhboac Hawtio Redhat service Registry |
|
References |
|
Tue, 10 Dec 2024 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | No description is available for this CVE. | |
Title | io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling | |
Weaknesses | CWE-444 | |
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2024-12-12T09:05:28.451Z
Updated: 2024-12-13T10:24:58.563Z
Reserved: 2024-12-10T01:22:12.303Z
Link: CVE-2024-12397
Vulnrichment
Updated: 2024-12-12T15:31:48.532Z
NVD
Status : Received
Published: 2024-12-12T09:15:05.570
Modified: 2024-12-12T09:15:05.570
Link: CVE-2024-12397
Redhat