Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-4853
HistorySep 20, 2023 - 10:15 a.m.

Design/Logic Flaw

2023-09-2010:15:00
PRIOn knowledge base
www.prio-n.com
6
quarkus
http
security flaw
unauthorized access
denial of service

7.5 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

58.7%

A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.

7.5 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

58.7%