DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2024-12397

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-12397

CGA ID

CGA-pmfx-5gr2-3p9m

Severity

7.4

High

CVSS V3

Summary

io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling

Description

A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images