THREAT OPS › Threat News › [NVD] CVE-2024-12397 (HIGH 7.4) — A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with
certain value-delimiting characters in incoming requests. This issue could
allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie
values or spoof arbitrary additional cookie values, leadi
[NVD] CVE-2024-12397 (HIGH 7.4) — A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leadi
CVE-2024-12397 CVSS: 7.4 HIGH Published: 2024-12-12T09:15:05.570
A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The ma
Indicators of compromise
- CVE-2024-12397cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-12397