Io.quarkus.http/quarkus-http-core: quarkus http cookie smuggling
Summary
| CVE | CVE-2024-12397 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-12-12 09:15:05 UTC |
| Updated | 2026-08-04 20:16:45 UTC |
| Description | A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity. |
Risk And Classification
Primary CVSS: v3.1 7.4 HIGH from [email protected]
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS: 0.007960000 probability, percentile 0.530100000 (date 2026-08-09)
Problem Types: CWE-444 | CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 7.4 | HIGH | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
| 3.1 | CNA | CVSS | 7.4 | HIGH | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
NoneCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Red Hat | Cryostat 4 On RHEL 9 | unaffected 0.5.0-6 * rpm | Not specified |
| CNA | Red Hat | Cryostat 4 On RHEL 9 | unaffected 4.0.0-7 * rpm | Not specified |
| CNA | Red Hat | Cryostat 4 On RHEL 9 | unaffected 4.0.0-7 * rpm | Not specified |
| CNA | Red Hat | Cryostat 4 On RHEL 9 | unaffected 4.0.0-7 * rpm | Not specified |
| CNA | Red Hat | Cryostat 4 On RHEL 9 | unaffected 4.0.0-7 * rpm | Not specified |
| CNA | Red Hat | Cryostat 4 On RHEL 9 | unaffected 4.0.0-7 * rpm | Not specified |
| CNA | Red Hat | Cryostat 4 On RHEL 9 | unaffected 4.0.0-7 * rpm | Not specified |
| CNA | Red Hat | Cryostat 4 On RHEL 9 | unaffected 4.0.0-7 * rpm | Not specified |
| CNA | Red Hat | Cryostat 4 On RHEL 9 | unaffected 4.0.0-7 * rpm | Not specified |
| CNA | Red Hat | Cryostat 4 On RHEL 9 | unaffected 4.0.0-7 * rpm | Not specified |
| CNA | Red Hat | Cryostat 4 On RHEL 9 | unaffected 4.0.0-7 * rpm | Not specified |
| CNA | Red Hat | HawtIO HawtIO 4.2.0 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Build Of Quarkus 3.15.3 | Not specified | Not specified |
| CNA | Red Hat | Cryostat 3 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Build Of Apache Camel 4 For Quarkus 3 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Build Of Apache Camel 4 For Quarkus 3 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Build Of Apicurio Registry 2 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Build Of Keycloak | Not specified | Not specified |
| CNA | Red Hat | Red Hat Build Of OptaPlanner 8 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Fuse 7 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Integration Camel K 1 | Not specified | Not specified |
| CNA | Red Hat | Red Hat JBoss Enterprise Application Platform 8 | Not specified | Not specified |
| CNA | Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | Not specified | Not specified |
| CNA | Red Hat | Red Hat Process Automation 7 | Not specified | Not specified |
| CNA | Red Hat | Streams For Apache Kafka | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| access.redhat.com/errata/RHSA-2025:0900 | [email protected] | access.redhat.com | |
| access.redhat.com/security/cve/CVE-2024-12397 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:3018 | [email protected] | access.redhat.com | |
| bugzilla.redhat.com/show_bug.cgi | [email protected] | bugzilla.redhat.com | |
| access.redhat.com/errata/RHSA-2025:8761 | [email protected] | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2024-12-10T01:15:33.380Z | Reported to Red Hat. |
| CNA | 2024-12-10T00:00:00.000Z | Made public. |
Workarounds
CNA: Currently, no mitigation is available for this vulnerability.
There are currently no legacy QID mappings associated with this CVE.