information leakage vulnerability
CVE-2024-4109
7.5HIGH
Key Information:
- Vendor
- Red Hat
- Status
- Vendor
- CVE Published:
- 12 December 2024
Summary
A flaw exists in Undertow, which could allow for an HTTP request header value from a previous stream to be incorrectly reused in a request associated with a subsequent stream over the same HTTP/2 connection. This could potentially result in sensitive information becoming inadvertently accessible across different requests, heightening the risk of information disclosure vulnerabilities. Organizations utilizing Undertow should review and apply the necessary mitigations to uphold the integrity of their data handling processes.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved