Quarkus

Quarkus

47 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 23.21%
  • Veröffentlicht 22.11.2022 19:15:18
  • Zuletzt bearbeitet 29.04.2025 17:15:38

A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 02.10.2022 05:15:09
  • Zuletzt bearbeitet 21.11.2024 07:24:15

In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choice...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 02.10.2022 05:15:09
  • Zuletzt bearbeitet 21.11.2024 07:24:15

In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enab...

Exploit
  • EPSS 12.22%
  • Veröffentlicht 31.08.2022 16:15:10
  • Zuletzt bearbeitet 21.11.2024 07:01:02

It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavior.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 23.03.2022 20:15:10
  • Zuletzt bearbeitet 21.11.2024 06:39:47

A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another in RestEasy Reactive. This flaw allows a low-privileged user to perform operations on the database with a different set of privileg...

Exploit
  • EPSS 4.81%
  • Veröffentlicht 02.02.2022 12:15:08
  • Zuletzt bearbeitet 05.05.2025 17:17:48

pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or propertie...

  • EPSS 0.3%
  • Veröffentlicht 19.01.2022 12:15:15
  • Zuletzt bearbeitet 21.11.2024 06:44:31

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple pro...

  • EPSS 0.18%
  • Veröffentlicht 09.12.2021 19:15:07
  • Zuletzt bearbeitet 21.11.2024 06:29:48

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / en...

  • EPSS 62.75%
  • Veröffentlicht 20.10.2021 11:16:17
  • Zuletzt bearbeitet 21.11.2024 06:03:11

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple pro...

  • EPSS 0.6%
  • Veröffentlicht 19.10.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 06:14:43

The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well...