ZeroHour

CVE-2023-4853

PoC
CVSS 3.1
8.1 high
EPSS
1%p72
Published
()
Modified
Description

A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.

Vendors
quarkusredhat
Products
quarkus, build of optaplanner, build of quarkus, decision manager, integration camel k, integration camel quarkus, integration service registry, jboss middleware, jboss middleware text-only advisories, openshift serverless, process automation manager, openshift container platform
Weakness
CWE-148, CWE-863
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.