Lucene search

K
githubGitHub Advisory DatabaseGHSA-3FHX-3VVG-2J84
HistoryJul 04, 2023 - 3:30 p.m.

quarkus-core vulnerable to client driven TLS cipher downgrading

2023-07-0415:30:18
GitHub Advisory Database
github.com
16
quarkus
tls
vulnerability
software

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

0.001 Low

EPSS

Percentile

24.8%

A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force the selection of the weaker supported TLS protocol.

Affected configurations

Vulners
Node
io.quarkus\quarkusMatchcore
CPENameOperatorVersion
io.quarkus:quarkus-corelt2.16.8.Final

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

0.001 Low

EPSS

Percentile

24.8%