CVE-2024-12397EPSS p56.1%
CVE-2024-12397CVE-2024-12397
Description
A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with
certain value-delimiting characters in incoming requests. This issue could
allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie
values or spoof arbitrary additional cookie values, leading to unauthorized
data access or modification. The main threat from this flaw impacts data
confidentiality and integrity.
Scoring
| CVSS | 7.4 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 0.83% probability of exploitation · percentile 56.1% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-04 |