← Back

CVE-2023-6394

nvd nist
Published: Dec 9, 2023Modified: Mar 24, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.

Affected (2)

1 product
Quarkus
1 product
Build Of Quarkus
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.6.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (7)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking

Timeline

No history available yet.