CVE-2023-4853
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD
Description
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.
Affected (17)
Products: Quarkus: Quarkus · Redhat: Build Of Optaplanner, Build Of Quarkus, Decision Manager, Integration Camel K, Integration Camel Quarkus, Integration Service Registry, Jboss Middleware, Jboss Middleware Text Only Advisories, Openshift Serverless, Process Automation Manager, Openshift Container Platform
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 | |
| From 2.13.0 to 2.13.8 | |
| Version 7.0 | |
| Before 1.10.2 | |
| All versions | |
| All versions | |
| Version 1 | |
| Version 1.0 | |
| All versions | |
| Version 7.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.10 |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux | Version 8.0 |
Related CWEs
CWE-148
Improper Neutralization of Input Leaders
The product does not properly handle when a leading character or sequence ("leader") is missing or malformed, or if multiple leaders are used when only one should be allowed.
CWE-863
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
References (24)
Source: secalert@redhat.com
MitigationVendor Advisory
Source: secalert@redhat.com
ExploitMitigationTechnical DescriptionVendor Advisory
Source: secalert@redhat.com
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationTechnical DescriptionVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Timeline
No history available yet.