Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS0zanJ2LWpncDgtNDV2M84ABBcA
Undertow incorrectly parses cookies
A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.
Permalink: https://github.com/advisories/GHSA-3jrv-jgp8-45v3JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zanJ2LWpncDgtNDV2M84ABBcA
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: 24 days ago
Updated: 22 days ago
CVSS Score: 7.4
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Percentage: 0.00098
EPSS Percentile: 0.42015
Identifiers: GHSA-3jrv-jgp8-45v3, CVE-2023-4639
References:
- https://nvd.nist.gov/vuln/detail/CVE-2023-4639
- https://access.redhat.com/errata/RHSA-2024:1674
- https://access.redhat.com/errata/RHSA-2024:1675
- https://access.redhat.com/errata/RHSA-2024:1676
- https://access.redhat.com/errata/RHSA-2024:1677
- https://access.redhat.com/errata/RHSA-2024:2763
- https://access.redhat.com/errata/RHSA-2024:2764
- https://access.redhat.com/errata/RHSA-2024:3919
- https://access.redhat.com/security/cve/CVE-2023-4639
- https://bugzilla.redhat.com/show_bug.cgi?id=2166022
- https://github.com/undertow-io/undertow/commit/1f93a979d2ac264798e5779b5b7172dfafe0066f
- https://github.com/advisories/GHSA-3jrv-jgp8-45v3
Blast Radius: 27.5
Affected Packages
maven:io.undertow:undertow-core
Dependent packages: 912Dependent repositories: 5,259
Downloads:
Affected Version Ranges: < 2.2.30.Final, >= 2.3.0.Alpha1, < 2.3.11.Final
Fixed in: 2.2.30.Final, 2.3.11.Final
All affected versions: 2.3.1-0.Final
All unaffected versions: