Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS0zanJ2LWpncDgtNDV2M84ABBcA

Undertow incorrectly parses cookies

A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.

Permalink: https://github.com/advisories/GHSA-3jrv-jgp8-45v3
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zanJ2LWpncDgtNDV2M84ABBcA
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: 4 days ago
Updated: 2 days ago


CVSS Score: 7.4
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Identifiers: GHSA-3jrv-jgp8-45v3, CVE-2023-4639
References: Repository: https://github.com/undertow-io/undertow
Blast Radius: 27.5

Affected Packages

maven:io.undertow:undertow-core
Dependent packages: 912
Dependent repositories: 5,259
Downloads:
Affected Version Ranges: < 2.2.30.Final, >= 2.3.0.Alpha1, < 2.3.11.Final
Fixed in: 2.2.30.Final, 2.3.11.Final
All affected versions: 2.3.1-0.Final
All unaffected versions: