CVE-2024-12397
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/12/2024
Last modified:
15/04/2026
Description
A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with<br />
certain value-delimiting characters in incoming requests. This issue could<br />
allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie<br />
values or spoof arbitrary additional cookie values, leading to unauthorized<br />
data access or modification. The main threat from this flaw impacts data<br />
confidentiality and integrity.
Impact
Base Score 3.x
7.40
Severity 3.x
HIGH



