Unauthorized Data Access via Incorrect Cookie Parsing
CVE-2023-4639

7.4HIGH

Summary

A flaw exists in the Undertow server, which improperly handles the parsing of cookies that contain specific value-delimiting characters in requests. This vulnerability enables potential attackers to craft malicious cookie values, enabling the exfiltration of HttpOnly cookie values or the spoofing of additional cookie values. Consequently, this can lead to unauthorized access to sensitive data and alterations, posing significant risks to the integrity and confidentiality of the affected applications.

Affected Version(s)

Migration Toolkit for Runtimes 1 on RHEL 8 1.2-23

Migration Toolkit for Runtimes 1 on RHEL 8 1.2-15

Migration Toolkit for Runtimes 1 on RHEL 8 1.2-16

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.