Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. io.undertow/undertow-core
  4. ›
  5. CVE-2023-4639

CVE-2023-4639: Undertow incorrectly parses cookies

November 17, 2024 (updated February 7, 2025)

A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.

References

  • access.redhat.com/errata/RHSA-2024:1674
  • access.redhat.com/errata/RHSA-2024:1675
  • access.redhat.com/errata/RHSA-2024:1676
  • access.redhat.com/errata/RHSA-2024:1677
  • access.redhat.com/errata/RHSA-2024:2763
  • access.redhat.com/errata/RHSA-2024:2764
  • access.redhat.com/errata/RHSA-2024:3919
  • access.redhat.com/security/cve/CVE-2023-4639
  • bugzilla.redhat.com/show_bug.cgi?id=2166022
  • github.com/advisories/GHSA-3jrv-jgp8-45v3
  • github.com/undertow-io/undertow
  • github.com/undertow-io/undertow/commit/1f93a979d2ac264798e5779b5b7172dfafe0066f
  • nvd.nist.gov/vuln/detail/CVE-2023-4639
  • security.netapp.com/advisory/ntap-20250207-0001

Code Behaviors & Features

Detect and mitigate CVE-2023-4639 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 2.3.0.Alpha1 before 2.3.11.Final, all versions before 2.2.30.Final

Fixed versions

  • 2.3.11.Final
  • 2.2.30.Final

Solution

Upgrade to versions 2.2.30.Final, 2.3.11.Final or above.

Impact 7.4 HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Source file

maven/io.undertow/undertow-core/CVE-2023-4639.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:28 +0000.