#VU103760 Input validation error in Quarkus - CVE-2024-12397
Published: February 11, 2025
Quarkus
Red Hat Inc.
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient validation of cookies with certain value-delimiting characters in incoming requests in Quarkus-HTTP. A remote attacker can construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification.