8.1 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
0.001 Low
EPSS
Percentile
24.8%
A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force the selection of the weaker supported TLS protocol.
CPE | Name | Operator | Version |
---|---|---|---|
io.quarkus:quarkus-core | lt | 2.16.8.Final |
access.redhat.com/errata/RHSA-2023:3809
access.redhat.com/security/cve/CVE-2023-2974
bugzilla.redhat.com/show_bug.cgi?id=2211026
github.com/advisories/GHSA-3fhx-3vvg-2j84
github.com/quarkusio/quarkus/commit/468397ae53a8d6aae933d0d406f94965e97d1935
github.com/quarkusio/quarkus/pull/34469
nvd.nist.gov/vuln/detail/CVE-2023-2974