CVE-2024-12397

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/12/2024
Last modified:
15/04/2026

Description

A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with<br /> certain value-delimiting characters in incoming requests. This issue could<br /> allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie<br /> values or spoof arbitrary additional cookie values, leading to unauthorized<br /> data access or modification. The main threat from this flaw impacts data<br /> confidentiality and integrity.