CVE-2023-4639

CVSS 3.1 Score 7.4 of 10 (high)

Details

Published Nov 17, 2024
Updated: Nov 18, 2024
CWE ID 444

Summary

CVE-2023-4639 is a vulnerability affecting Undertow, a Java web server. The issue arises from its incorrect parsing of cookies with specific value-delimiting characters in incoming requests. Attackers can exploit this flaw to exfiltrate HttpOnly cookie values or spoof additional cookie values, leading to unauthorized data access or modification. The primary threats from this vulnerability involve data confidentiality and integrity.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share