information leakage vulnerability
CVE-2024-4109

7.5HIGH

Summary

A flaw exists in Undertow, which could allow for an HTTP request header value from a previous stream to be incorrectly reused in a request associated with a subsequent stream over the same HTTP/2 connection. This could potentially result in sensitive information becoming inadvertently accessible across different requests, heightening the risk of information disclosure vulnerabilities. Organizations utilizing Undertow should review and apply the necessary mitigations to uphold the integrity of their data handling processes.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.