CVE-2023-4639
published 2024-11-17CVE-2023-4639: A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an…
PriorityP347high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
1.12%
62.5th percentile
A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 2.3.18-1 (forky) | undertow 2.3.18-1 (forky) |
| redhat | undertow | >= 0 < 2.3.18-1 | 2.3.18-1 |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
osv7.4HIGH
vendor_debian7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling
vendor_redhat·2024-12-10·CVSS 7.4
CVE-2024-12397 [HIGH] CWE-444 io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling
io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling
A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with
certain value-delimiting characters in incoming requests. This issue could
allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie
values or spoof arbitrary additional cookie values, leading to unauthorized
data access or modification. The main threat from this flaw impacts data
confidentiality and integrity.
A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with
certain value-delimiting characters in incoming requests. This issue could
allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie
values or spoof arbitrary additional cookie values, leading to unauthorized
data access or modification. Th
Red Hat
undertow: Cookie Smuggling/Spoofing
vendor_redhat·2024-02-08·CVSS 7.4
CVE-2023-4639 [HIGH] CWE-444 undertow: Cookie Smuggling/Spoofing
undertow: Cookie Smuggling/Spoofing
A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.
A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts
Debian
CVE-2023-4639: undertow - A flaw was found in Undertow, which incorrectly parses cookies with certain valu...
vendor_debian·2023·CVSS 7.4
CVE-2023-4639 [HIGH] CVE-2023-4639: undertow - A flaw was found in Undertow, which incorrectly parses cookies with certain valu...
A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.
Scope: local
forky: resolved (fixed in 2.3.18-1)
sid: resolved (fixed in 2.3.18-1)
GHSA
Undertow incorrectly parses cookies
ghsa·2024-11-17
CVE-2023-4639 [HIGH] CWE-444 Undertow incorrectly parses cookies
Undertow incorrectly parses cookies
A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.
OSV
CVE-2023-4639: A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests
osv·2024-11-17·CVSS 7.4
CVE-2023-4639 [HIGH] CVE-2023-4639: A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests
A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.
OSV
Undertow incorrectly parses cookies
osv·2024-11-17
CVE-2023-4639 [HIGH] Undertow incorrectly parses cookies
Undertow incorrectly parses cookies
A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2024:1674https://access.redhat.com/errata/RHSA-2024:1675https://access.redhat.com/errata/RHSA-2024:1676https://access.redhat.com/errata/RHSA-2024:1677https://access.redhat.com/errata/RHSA-2024:2763https://access.redhat.com/errata/RHSA-2024:2764https://access.redhat.com/errata/RHSA-2024:3919https://access.redhat.com/security/cve/CVE-2023-4639https://bugzilla.redhat.com/show_bug.cgi?id=2166022https://security.netapp.com/advisory/ntap-20250207-0001/
2024-11-17
Published