information leakage vulnerability
CVE-2024-4109
7.5HIGH
Key Information
- Vendor
- Red Hat
- Status
- Red Hat Build Of Apache Camel For Spring Boot 3
- Red Hat Build Of Apache Camel For Spring Boot 4
- Red Hat Build Of Apache Camel - Hawtio
- Red Hat Build Of Keycloak
- Vendor
- CVE Published:
- 12 December 2024
Summary
A flaw was found in Undertow. An HTTP request header value from a previous stream may be incorrectly reused for a request associated with a subsequent stream on the same HTTP/2 connection. This issue can potentially lead to information leakage between requests.
Refferences
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database