DirectorySecurity Advisories
Sign In
Security Advisories

CGA-x8vm-j96x-4fxq

Published

Last updated

https://images.chainguard.dev/security/CGA-x8vm-j96x-4fxq
Package

keycloak

Latest Update
Fixed
Fixed Version

26.0.7-r1

Aliases
  • GHSA-cxrx-q234-m22m

Severity

7.4

High

CVSS V3

Summary

io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling

Description

A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images