#VU88155 Input validation error in Undertow - CVE-2023-4639
Published: April 4, 2024
Undertow
Red Hat Inc.
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient validation of cookies with certain value-delimiting characters in incoming requests. A remote attacker can construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification.