GHSA-cxrx-q234-m22m

Suggest an improvement
Source
https://github.com/advisories/GHSA-cxrx-q234-m22m
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-cxrx-q234-m22m/GHSA-cxrx-q234-m22m.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-cxrx-q234-m22m
Aliases
  • CVE-2024-12397
Related
Published
2024-12-12T09:31:35Z
Modified
2024-12-12T19:27:11.789595Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling
Details

A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.

Database specific
{
    "nvd_published_at": "2024-12-12T09:15:05Z",
    "cwe_ids": [
        "CWE-444"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2024-12-12T19:19:40Z"
}
References

Affected packages

Maven / io.quarkus.http:quarkus-http-core

Package

Name
io.quarkus.http:quarkus-http-core
View open source insights on deps.dev
Purl
pkg:maven/io.quarkus.http/quarkus-http-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.3.4

Affected versions

3.*

3.0.0.Alpha1
3.0.0.Alpha2
3.0.0.Alpha3
3.0.0.Alpha4
3.0.0.Alpha5
3.0.0.Alpha6
3.0.0.Alpha7
3.0.0.Beta1
3.0.0.Beta2
3.0.0.Beta3
3.0.0.Final
3.0.1.Final
3.0.2.Final
3.0.3.Final
3.0.4.Final
3.0.5.Final
3.0.6.Final
3.0.7.Final
3.0.8.Final
3.0.9.Final
3.0.10.Final
3.0.11.Final
3.0.12.Final
3.0.13.Final
3.0.14.Final
3.0.15.Final
3.0.16.Final
3.0.17.Final
3.0.18.Final
3.1.0.Beta1
3.1.0.Beta2
3.1.0.Final
3.1.1.Final

4.*

4.0.0.Alpha2
4.0.0.Alpha3
4.0.0.Alpha4
4.0.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.1.9
4.2.1

5.*

5.0.0.Alpha1
5.0.0.Alpha2
5.0.0.Alpha3
5.0.0.Final
5.0.1.Final
5.0.2.Final
5.0.3.Final
5.1.0.Final
5.2.0.Final
5.2.1.Final
5.2.2.Final
5.2.3
5.2.4
5.3.0
5.3.1
5.3.2
5.3.3