8.1
CVE-2023-4853
- EPSS 0.35%
- Veröffentlicht 20.09.2023 10:15:14
- Zuletzt bearbeitet 21.11.2024 08:36:06
- Quelle secalert@redhat.com
- Teams Watchlist Login
- Unerledigt Login
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Build Of Optaplanner Version8.0
Redhat ≫ Build Of Quarkus SwEditiontext-only Version >= 2.13.0 < 2.13.8
Redhat ≫ Decision Manager Version7.0
Redhat ≫ Integration Camel K Version < 1.10.2
Redhat ≫ Integration Camel Quarkus Version-
Redhat ≫ Integration Service Registry Version-
Redhat ≫ Jboss Middleware Version1
Redhat ≫ Jboss Middleware Text-only Advisories Version1.0 SwPlatformmiddleware
Redhat ≫ Openshift Serverless Version-
Redhat ≫ Openshift Serverless Version1.0
Redhat ≫ Process Automation Manager Version7.0
Redhat ≫ Openshift Container Platform Version4.10
Redhat ≫ Openshift Container Platform Version4.11
Redhat ≫ Openshift Container Platform Version4.12
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.35% | 0.566 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
secalert@redhat.com | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-148 Improper Neutralization of Input Leaders
The product does not properly handle when a leading character or sequence ("leader") is missing or malformed, or if multiple leaders are used when only one should be allowed.
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.