ZeroHour

CVE-2023-0044

CVSS 3.1
6.1 medium
EPSS
<1%p44
Published
()
Modified
Description

If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented with the Quarkus CSRF Prevention feature.

Vendors
quarkusredhat
Products
quarkus, build of quarkus
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.