We found results for “”
CVE-2023-4853
Good to know:
Date: September 20, 2023
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.
Language: Java
Severity Score
Related Resources (18)
Severity Score
Weakness Type (CWE)
Top Fix
Upgrade Version
Upgrade to version io.quarkus:quarkus-csrf-reactive:2.16.11.Final,3.2.6.Final,3.3.3;io.quarkus:quarkus-keycloak-authorization:2.16.11.Final,3.2.6.Final,3.3.3;io.quarkus:quarkus-undertow:2.16.11.Final,3.2.6.Final,3.3.3;io.quarkus:quarkus-vertx-http:2.16.11.Final,3.2.6.Final,3.3.3
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | HIGH |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |