A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.
History

Thu, 12 Dec 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 12 Dec 2024 09:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.
Title io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling Io.quarkus.http/quarkus-http-core: quarkus http cookie smuggling
First Time appeared Redhat
Redhat amq Streams
Redhat build Keycloak
Redhat camel Quarkus
Redhat cryostat
Redhat integration
Redhat jboss Enterprise Application Platform
Redhat jboss Enterprise Bpms Platform
Redhat jboss Fuse
Redhat jbosseapxp
Redhat optaplanner
Redhat quarkus
Redhat rhboac Hawtio
Redhat service Registry
CPEs cpe:/a:redhat:amq_streams:1
cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:camel_quarkus:3
cpe:/a:redhat:cryostat:3
cpe:/a:redhat:integration:1
cpe:/a:redhat:jboss_enterprise_application_platform:8
cpe:/a:redhat:jboss_enterprise_bpms_platform:7
cpe:/a:redhat:jboss_fuse:7
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:optaplanner:::el6
cpe:/a:redhat:quarkus:3
cpe:/a:redhat:rhboac_hawtio:4
cpe:/a:redhat:service_registry:2
Vendors & Products Redhat
Redhat amq Streams
Redhat build Keycloak
Redhat camel Quarkus
Redhat cryostat
Redhat integration
Redhat jboss Enterprise Application Platform
Redhat jboss Enterprise Bpms Platform
Redhat jboss Fuse
Redhat jbosseapxp
Redhat optaplanner
Redhat quarkus
Redhat rhboac Hawtio
Redhat service Registry
References

Tue, 10 Dec 2024 14:00:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling
Weaknesses CWE-444
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2024-12-12T09:05:28.451Z

Updated: 2024-12-13T10:24:58.563Z

Reserved: 2024-12-10T01:22:12.303Z

Link: CVE-2024-12397

cve-icon Vulnrichment

Updated: 2024-12-12T15:31:48.532Z

cve-icon NVD

Status : Received

Published: 2024-12-12T09:15:05.570

Modified: 2024-12-12T09:15:05.570

Link: CVE-2024-12397

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-12-10T00:00:00Z

Links: CVE-2024-12397 - Bugzilla