Unauthorized Data Access via Incorrect Cookie Parsing
CVE-2023-4639
Key Information:
What is CVE-2023-4639?
A flaw exists in the Undertow server, which improperly handles the parsing of cookies that contain specific value-delimiting characters in requests. This vulnerability enables potential attackers to craft malicious cookie values, enabling the exfiltration of HttpOnly cookie values or the spoofing of additional cookie values. Consequently, this can lead to unauthorized access to sensitive data and alterations, posing significant risks to the integrity and confidentiality of the affected applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Migration Toolkit for Runtimes 1 on RHEL 8 1.2-23
Migration Toolkit for Runtimes 1 on RHEL 8 1.2-15
Migration Toolkit for Runtimes 1 on RHEL 8 1.2-16
References
CVSS V3.1
Timeline
Vulnerability published