ZeroHour

CVE-2023-2974

CVSS 3.1
8.1 high
EPSS
<1%p57
Published
()
Modified
Description

A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force the selection of the weaker supported TLS protocol.

Vendors
redhat
Products
build of quarkus
Weakness
CWE-757
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.