CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
70.4%
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.
Vendor | Product | Version | CPE |
---|---|---|---|
quarkus | quarkus | * | cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:* |
redhat | build_of_optaplanner | 8.0 | cpe:2.3:a:redhat:build_of_optaplanner:8.0:*:*:*:*:*:*:* |
redhat | build_of_quarkus | * | cpe:2.3:a:redhat:build_of_quarkus:*:*:*:*:text-only:*:*:* |
redhat | decision_manager | 7.0 | cpe:2.3:a:redhat:decision_manager:7.0:*:*:*:*:*:*:* |
redhat | integration_camel_k | * | cpe:2.3:a:redhat:integration_camel_k:*:*:*:*:*:*:*:* |
redhat | integration_camel_quarkus | - | cpe:2.3:a:redhat:integration_camel_quarkus:-:*:*:*:*:*:*:* |
redhat | integration_service_registry | - | cpe:2.3:a:redhat:integration_service_registry:-:*:*:*:*:*:*:* |
redhat | jboss_middleware | 1 | cpe:2.3:a:redhat:jboss_middleware:1:*:*:*:*:*:*:* |
redhat | jboss_middleware_text-only_advisories | 1.0 | cpe:2.3:a:redhat:jboss_middleware_text-only_advisories:1.0:*:*:*:*:middleware:*:* |
redhat | openshift_serverless | - | cpe:2.3:a:redhat:openshift_serverless:-:*:*:*:*:*:*:* |
[
{
"vendor": "Red Hat",
"product": "Openshift Serverless 1 on RHEL 8",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"packageName": "openshift-serverless-clients",
"defaultStatus": "affected",
"versions": [
{
"version": "0:1.9.2-3.el8",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
}
],
"cpes": [
"cpe:/a:redhat:serverless:1.0::el8"
]
},
{
"vendor": "Red Hat",
"product": "Red Hat build of Quarkus 2.13.8.SP2",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"packageName": "io.quarkus/quarkus-keycloak-authorization",
"defaultStatus": "affected",
"versions": [
{
"version": "2.13.8.Final-redhat-00005",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
}
],
"cpes": [
"cpe:/a:redhat:quarkus:2.13"
]
},
{
"vendor": "Red Hat",
"product": "Red Hat build of Quarkus 2.13.8.SP2",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"packageName": "io.quarkus/quarkus-undertow",
"defaultStatus": "affected",
"versions": [
{
"version": "2.13.8.Final-redhat-00005",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
}
],
"cpes": [
"cpe:/a:redhat:quarkus:2.13"
]
},
{
"vendor": "Red Hat",
"product": "Red Hat build of Quarkus 2.13.8.SP2",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"packageName": "io.quarkus/quarkus-vertx-http",
"defaultStatus": "affected",
"versions": [
{
"version": "2.13.8.Final-redhat-00005",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
}
],
"cpes": [
"cpe:/a:redhat:quarkus:2.13"
]
},
{
"vendor": "Red Hat",
"product": "Red Hat Camel Extensions for Quarkus 2.13.3-1",
"collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html",
"defaultStatus": "unaffected",
"packageName": "quarkus-vertx-http",
"cpes": [
"cpe:/a:redhat:camel_quarkus:2.13"
]
},
{
"vendor": "Red Hat",
"product": "Red Hat OpenShift Serverless 1.30",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"packageName": "openshift-serverless-1/client-kn-rhel8",
"defaultStatus": "affected",
"versions": [
{
"version": "1.9.2-3",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
}
],
"cpes": [
"cpe:/a:redhat:openshift_serverless:1.30::el8"
]
},
{
"vendor": "Red Hat",
"product": "Red Hat OpenShift Serverless 1.30",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"packageName": "openshift-serverless-1/ingress-rhel8-operator",
"defaultStatus": "affected",
"versions": [
{
"version": "1.30.1-1",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
}
],
"cpes": [
"cpe:/a:redhat:openshift_serverless:1.30::el8"
]
},
{
"vendor": "Red Hat",
"product": "Red Hat OpenShift Serverless 1.30",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"packageName": "openshift-serverless-1/knative-rhel8-operator",
"defaultStatus": "affected",
"versions": [
{
"version": "1.30.1-1",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
}
],
"cpes": [
"cpe:/a:redhat:openshift_serverless:1.30::el8"
]
},
{
"vendor": "Red Hat",
"product": "Red Hat OpenShift Serverless 1.30",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"packageName": "openshift-serverless-1/kn-cli-artifacts-rhel8",
"defaultStatus": "affected",
"versions": [
{
"version": "1.9.2-3",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
}
],
"cpes": [
"cpe:/a:redhat:openshift_serverless:1.30::el8"
]
},
{
"vendor": "Red Hat",
"product": "Red Hat OpenShift Serverless 1.30",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"packageName": "openshift-serverless-1/serverless-operator-bundle",
"defaultStatus": "affected",
"versions": [
{
"version": "1.30.1-1",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
}
],
"cpes": [
"cpe:/a:redhat:openshift_serverless:1.30::el8"
]
},
{
"vendor": "Red Hat",
"product": "Red Hat OpenShift Serverless 1.30",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"packageName": "openshift-serverless-1/serverless-rhel8-operator",
"defaultStatus": "affected",
"versions": [
{
"version": "1.30.1-1",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
}
],
"cpes": [
"cpe:/a:redhat:openshift_serverless:1.30::el8"
]
},
{
"vendor": "Red Hat",
"product": "Red Hat OpenShift Serverless 1.30",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"packageName": "openshift-serverless-1/svls-must-gather-rhel8",
"defaultStatus": "affected",
"versions": [
{
"version": "1.30.1-1",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
}
],
"cpes": [
"cpe:/a:redhat:openshift_serverless:1.30::el8"
]
},
{
"vendor": "Red Hat",
"product": "Red Hat OpenShift Serverless 1.30",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"packageName": "openshift-serverless-1-tech-preview/logic-data-index-ephemeral-rhel8",
"defaultStatus": "affected",
"versions": [
{
"version": "1.30.0-5",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
}
],
"cpes": [
"cpe:/a:redhat:openshift_serverless:1.30::el8"
]
},
{
"vendor": "Red Hat",
"product": "Red Hat OpenShift Serverless 1.30",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"packageName": "openshift-serverless-1-tech-preview/logic-swf-builder-rhel8",
"defaultStatus": "affected",
"versions": [
{
"version": "1.30.0-6",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
}
],
"cpes": [
"cpe:/a:redhat:openshift_serverless:1.30::el8"
]
},
{
"vendor": "Red Hat",
"product": "Red Hat OpenShift Serverless 1.30",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"packageName": "openshift-serverless-1-tech-preview/logic-swf-devmode-rhel8",
"defaultStatus": "affected",
"versions": [
{
"version": "1.30.0-6",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
}
],
"cpes": [
"cpe:/a:redhat:openshift_serverless:1.30::el8"
]
},
{
"vendor": "Red Hat",
"product": "RHBOP Text-Only",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected",
"packageName": "quarkus-vertx-http",
"cpes": [
"cpe:/a:redhat:optaplanner:::el6"
]
},
{
"vendor": "Red Hat",
"product": "RHEL-8 based Middleware Containers",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"packageName": "rhpam-7/rhpam-kogito-builder-rhel8",
"defaultStatus": "affected",
"versions": [
{
"version": "7.13.4-3",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
}
],
"cpes": [
"cpe:/a:redhat:rhosemc:1.0::el8"
]
},
{
"vendor": "Red Hat",
"product": "RHEL-8 based Middleware Containers",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"packageName": "rhpam-7/rhpam-kogito-rhel8-operator",
"defaultStatus": "affected",
"versions": [
{
"version": "7.13.4-2",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
}
],
"cpes": [
"cpe:/a:redhat:rhosemc:1.0::el8"
]
},
{
"vendor": "Red Hat",
"product": "RHEL-8 based Middleware Containers",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"packageName": "rhpam-7/rhpam-kogito-rhel8-operator-bundle",
"defaultStatus": "affected",
"versions": [
{
"version": "7.13.4-2",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
}
],
"cpes": [
"cpe:/a:redhat:rhosemc:1.0::el8"
]
},
{
"vendor": "Red Hat",
"product": "RHEL-8 based Middleware Containers",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"packageName": "rhpam-7/rhpam-kogito-runtime-jvm-rhel8",
"defaultStatus": "affected",
"versions": [
{
"version": "7.13.4-3",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
}
],
"cpes": [
"cpe:/a:redhat:rhosemc:1.0::el8"
]
},
{
"vendor": "Red Hat",
"product": "RHEL-8 based Middleware Containers",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"packageName": "rhpam-7-tech-preview/rhpam-kogito-runtime-native-rhel8",
"defaultStatus": "affected",
"versions": [
{
"version": "7.13.4-3",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
}
],
"cpes": [
"cpe:/a:redhat:rhosemc:1.0::el8"
]
},
{
"vendor": "Red Hat",
"product": "RHINT Camel-K-1.10.2",
"collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html",
"defaultStatus": "unaffected",
"packageName": "quarkus-vertx-http",
"cpes": [
"cpe:/a:redhat:camel_k:1"
]
},
{
"vendor": "Red Hat",
"product": "RHINT Service Registry 2.5.4 GA",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected",
"packageName": "quarkus-vertx-http",
"cpes": [
"cpe:/a:redhat:service_registry:2.5"
]
},
{
"vendor": "Red Hat",
"product": "RHPAM 7.13.4 async",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected",
"cpes": [
"cpe:/a:redhat:jboss_enterprise_bpms_platform:7.13"
]
},
{
"vendor": "Red Hat",
"product": "Red Hat Process Automation 7",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"packageName": "quarkus-vertx-http",
"defaultStatus": "affected",
"cpes": [
"cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
]
}
]
access.redhat.com/errata/RHSA-2023:5170
access.redhat.com/errata/RHSA-2023:5310
access.redhat.com/errata/RHSA-2023:5337
access.redhat.com/errata/RHSA-2023:5446
access.redhat.com/errata/RHSA-2023:5479
access.redhat.com/errata/RHSA-2023:5480
access.redhat.com/errata/RHSA-2023:6107
access.redhat.com/errata/RHSA-2023:6112
access.redhat.com/errata/RHSA-2023:7653
access.redhat.com/security/cve/CVE-2023-4853
access.redhat.com/security/vulnerabilities/RHSB-2023-002
bugzilla.redhat.com/show_bug.cgi?id=2238034