Lucene search

K
cveRedhatCVE-2023-4853
HistorySep 20, 2023 - 10:15 a.m.

CVE-2023-4853

2023-09-2010:15:14
CWE-148
CWE-863
redhat
web.nvd.nist.gov
138
quarkus
http
security policies
bypass
unauthorized access
denial of service
nvd
cve-2023-4853

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0.003

Percentile

70.4%

A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.

Affected configurations

Nvd
Node
quarkusquarkusRange<2.16.11
OR
quarkusquarkusRange3.2.03.2.6
OR
quarkusquarkusRange3.3.03.3.3
Node
redhatbuild_of_optaplannerMatch8.0
OR
redhatbuild_of_quarkusRange2.13.02.13.8text-only
OR
redhatdecision_managerMatch7.0
OR
redhatintegration_camel_kRange<1.10.2
OR
redhatintegration_camel_quarkusMatch-
OR
redhatintegration_service_registryMatch-
OR
redhatjboss_middlewareMatch1
OR
redhatjboss_middleware_text-only_advisoriesMatch1.0middleware
OR
redhatopenshift_serverlessMatch-
OR
redhatopenshift_serverlessMatch1.0
OR
redhatprocess_automation_managerMatch7.0
Node
redhatenterprise_linuxMatch8.0
AND
redhatopenshift_container_platformMatch4.10
OR
redhatopenshift_container_platformMatch4.11
OR
redhatopenshift_container_platformMatch4.12
VendorProductVersionCPE
quarkusquarkus*cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:*
redhatbuild_of_optaplanner8.0cpe:2.3:a:redhat:build_of_optaplanner:8.0:*:*:*:*:*:*:*
redhatbuild_of_quarkus*cpe:2.3:a:redhat:build_of_quarkus:*:*:*:*:text-only:*:*:*
redhatdecision_manager7.0cpe:2.3:a:redhat:decision_manager:7.0:*:*:*:*:*:*:*
redhatintegration_camel_k*cpe:2.3:a:redhat:integration_camel_k:*:*:*:*:*:*:*:*
redhatintegration_camel_quarkus-cpe:2.3:a:redhat:integration_camel_quarkus:-:*:*:*:*:*:*:*
redhatintegration_service_registry-cpe:2.3:a:redhat:integration_service_registry:-:*:*:*:*:*:*:*
redhatjboss_middleware1cpe:2.3:a:redhat:jboss_middleware:1:*:*:*:*:*:*:*
redhatjboss_middleware_text-only_advisories1.0cpe:2.3:a:redhat:jboss_middleware_text-only_advisories:1.0:*:*:*:*:middleware:*:*
redhatopenshift_serverless-cpe:2.3:a:redhat:openshift_serverless:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 161

CNA Affected

[
  {
    "vendor": "Red Hat",
    "product": "Openshift Serverless 1 on RHEL 8",
    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
    "packageName": "openshift-serverless-clients",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "0:1.9.2-3.el8",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:serverless:1.0::el8"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat build of Quarkus 2.13.8.SP2",
    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
    "packageName": "io.quarkus/quarkus-keycloak-authorization",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "2.13.8.Final-redhat-00005",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:quarkus:2.13"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat build of Quarkus 2.13.8.SP2",
    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
    "packageName": "io.quarkus/quarkus-undertow",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "2.13.8.Final-redhat-00005",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:quarkus:2.13"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat build of Quarkus 2.13.8.SP2",
    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
    "packageName": "io.quarkus/quarkus-vertx-http",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "2.13.8.Final-redhat-00005",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:quarkus:2.13"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat Camel Extensions for Quarkus 2.13.3-1",
    "collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html",
    "defaultStatus": "unaffected",
    "packageName": "quarkus-vertx-http",
    "cpes": [
      "cpe:/a:redhat:camel_quarkus:2.13"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat OpenShift Serverless 1.30",
    "collectionURL": "https://catalog.redhat.com/software/containers/",
    "packageName": "openshift-serverless-1/client-kn-rhel8",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "1.9.2-3",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:openshift_serverless:1.30::el8"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat OpenShift Serverless 1.30",
    "collectionURL": "https://catalog.redhat.com/software/containers/",
    "packageName": "openshift-serverless-1/ingress-rhel8-operator",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "1.30.1-1",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:openshift_serverless:1.30::el8"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat OpenShift Serverless 1.30",
    "collectionURL": "https://catalog.redhat.com/software/containers/",
    "packageName": "openshift-serverless-1/knative-rhel8-operator",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "1.30.1-1",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:openshift_serverless:1.30::el8"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat OpenShift Serverless 1.30",
    "collectionURL": "https://catalog.redhat.com/software/containers/",
    "packageName": "openshift-serverless-1/kn-cli-artifacts-rhel8",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "1.9.2-3",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:openshift_serverless:1.30::el8"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat OpenShift Serverless 1.30",
    "collectionURL": "https://catalog.redhat.com/software/containers/",
    "packageName": "openshift-serverless-1/serverless-operator-bundle",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "1.30.1-1",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:openshift_serverless:1.30::el8"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat OpenShift Serverless 1.30",
    "collectionURL": "https://catalog.redhat.com/software/containers/",
    "packageName": "openshift-serverless-1/serverless-rhel8-operator",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "1.30.1-1",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:openshift_serverless:1.30::el8"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat OpenShift Serverless 1.30",
    "collectionURL": "https://catalog.redhat.com/software/containers/",
    "packageName": "openshift-serverless-1/svls-must-gather-rhel8",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "1.30.1-1",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:openshift_serverless:1.30::el8"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat OpenShift Serverless 1.30",
    "collectionURL": "https://catalog.redhat.com/software/containers/",
    "packageName": "openshift-serverless-1-tech-preview/logic-data-index-ephemeral-rhel8",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "1.30.0-5",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:openshift_serverless:1.30::el8"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat OpenShift Serverless 1.30",
    "collectionURL": "https://catalog.redhat.com/software/containers/",
    "packageName": "openshift-serverless-1-tech-preview/logic-swf-builder-rhel8",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "1.30.0-6",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:openshift_serverless:1.30::el8"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat OpenShift Serverless 1.30",
    "collectionURL": "https://catalog.redhat.com/software/containers/",
    "packageName": "openshift-serverless-1-tech-preview/logic-swf-devmode-rhel8",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "1.30.0-6",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:openshift_serverless:1.30::el8"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "RHBOP Text-Only",
    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
    "defaultStatus": "unaffected",
    "packageName": "quarkus-vertx-http",
    "cpes": [
      "cpe:/a:redhat:optaplanner:::el6"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "RHEL-8 based Middleware Containers",
    "collectionURL": "https://catalog.redhat.com/software/containers/",
    "packageName": "rhpam-7/rhpam-kogito-builder-rhel8",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "7.13.4-3",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:rhosemc:1.0::el8"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "RHEL-8 based Middleware Containers",
    "collectionURL": "https://catalog.redhat.com/software/containers/",
    "packageName": "rhpam-7/rhpam-kogito-rhel8-operator",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "7.13.4-2",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:rhosemc:1.0::el8"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "RHEL-8 based Middleware Containers",
    "collectionURL": "https://catalog.redhat.com/software/containers/",
    "packageName": "rhpam-7/rhpam-kogito-rhel8-operator-bundle",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "7.13.4-2",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:rhosemc:1.0::el8"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "RHEL-8 based Middleware Containers",
    "collectionURL": "https://catalog.redhat.com/software/containers/",
    "packageName": "rhpam-7/rhpam-kogito-runtime-jvm-rhel8",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "7.13.4-3",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:rhosemc:1.0::el8"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "RHEL-8 based Middleware Containers",
    "collectionURL": "https://catalog.redhat.com/software/containers/",
    "packageName": "rhpam-7-tech-preview/rhpam-kogito-runtime-native-rhel8",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "7.13.4-3",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:rhosemc:1.0::el8"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "RHINT Camel-K-1.10.2",
    "collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html",
    "defaultStatus": "unaffected",
    "packageName": "quarkus-vertx-http",
    "cpes": [
      "cpe:/a:redhat:camel_k:1"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "RHINT Service Registry 2.5.4 GA",
    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
    "defaultStatus": "unaffected",
    "packageName": "quarkus-vertx-http",
    "cpes": [
      "cpe:/a:redhat:service_registry:2.5"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "RHPAM 7.13.4 async",
    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
    "defaultStatus": "unaffected",
    "cpes": [
      "cpe:/a:redhat:jboss_enterprise_bpms_platform:7.13"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat Process Automation 7",
    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
    "packageName": "quarkus-vertx-http",
    "defaultStatus": "affected",
    "cpes": [
      "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
    ]
  }
]

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0.003

Percentile

70.4%