Lucene search

K
cvelistRedhatCVELIST:CVE-2023-0044
HistoryFeb 23, 2023 - 12:00 a.m.

CVE-2023-0044

2023-02-2300:00:00
redhat
www.cve.org
quarkus
form authentication
path attribute
vulnerability
cross-site attack
information disclosure
csrf prevention

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.6%

If the Quarkus Form Authentication session cookie Path attribute is set to / then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented with the Quarkus CSRF Prevention feature.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "quarkus-vertx-http",
    "versions": [
      {
        "version": "1.11.7",
        "status": "affected"
      }
    ]
  }
]

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.6%