CVE-2023-4853
PoC —CVSS 3.1
8.1 high
EPSS
1%p72
Published
()
Modified
Description
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.
- Vendors
- quarkusredhat
- Products
- quarkus, build of optaplanner, build of quarkus, decision manager, integration camel k, integration camel quarkus, integration service registry, jboss middleware, jboss middleware text-only advisories, openshift serverless, process automation manager, openshift container platform
- Weakness
- CWE-148, CWE-863
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.