A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.
Metrics
Affected Vendors & Products
References
History
Sun, 17 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sun, 17 Nov 2024 10:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | undertow: Cookie Smuggling/Spoofing | Undertow: cookie smuggling/spoofing |
First Time appeared |
Redhat camel Quarkus
Redhat camel Spring Boot Redhat integration Redhat jboss Data Grid Redhat jboss Enterprise Bpms Platform Redhat jboss Enterprise Brms Platform Redhat jboss Fuse Redhat jboss Fuse Service Works Redhat migration Toolkit Applications Redhat quarkus Redhat red Hat Single Sign On Redhat service Registry |
|
CPEs | cpe:/a:redhat:camel_quarkus:2 cpe:/a:redhat:camel_spring_boot:3 cpe:/a:redhat:integration:1 cpe:/a:redhat:jboss_data_grid:7 cpe:/a:redhat:jboss_data_grid:8 cpe:/a:redhat:jboss_enterprise_application_platform:6 cpe:/a:redhat:jboss_enterprise_bpms_platform:7 cpe:/a:redhat:jboss_enterprise_brms_platform:7 cpe:/a:redhat:jboss_fuse:6 cpe:/a:redhat:jboss_fuse:7 cpe:/a:redhat:jboss_fuse_service_works:6 cpe:/a:redhat:migration_toolkit_applications:6 cpe:/a:redhat:quarkus:2 cpe:/a:redhat:red_hat_single_sign_on:7 cpe:/a:redhat:service_registry:2 |
|
Vendors & Products |
Redhat camel Quarkus
Redhat camel Spring Boot Redhat integration Redhat jboss Data Grid Redhat jboss Enterprise Bpms Platform Redhat jboss Enterprise Brms Platform Redhat jboss Fuse Redhat jboss Fuse Service Works Redhat migration Toolkit Applications Redhat quarkus Redhat red Hat Single Sign On Redhat service Registry |
|
References |
|
|
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2024-11-17T10:21:44.539Z
Updated: 2024-11-17T16:17:46.027Z
Reserved: 2023-08-30T14:52:04.007Z
Link: CVE-2023-4639
Vulnrichment
Updated: 2024-11-17T16:17:40.737Z
NVD
Status : Awaiting Analysis
Published: 2024-11-17T11:15:05.840
Modified: 2024-11-18T17:11:17.393
Link: CVE-2023-4639
Redhat