Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8j3x-w35r-rw4r

Опубликовано: 25 янв. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.8
CVSS3: 8.6

Описание

Quarkus Improper Handling of Insufficient Permissions or Privileges and Improper Handling of Exceptional Conditions vulnerability

A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource may consume is being processed (deserialized) prior to the security constraints being evaluated and applied. This does not happen with configuration based security.

Пакеты

Наименование

io.quarkus.resteasy.reactive:resteasy-reactive

maven
Затронутые версииВерсия исправления

< 2.13.9.Final

2.13.9.Final

Наименование

io.quarkus.resteasy.reactive:resteasy-reactive

maven
Затронутые версииВерсия исправления

>= 3.0.0.Final, < 3.2.9.Final

3.2.9.Final

EPSS

Процентиль: 69%
0.00601
Низкий

8.8 High

CVSS4

8.6 High

CVSS3

Дефекты

CWE-280
CWE-502
CWE-755

Связанные уязвимости

CVSS3: 8.6
redhat
около 2 лет назад

A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource may consume is being processed (deserialized) prior to the security constraints being evaluated and applied. This does not happen with configuration based security.

CVSS3: 8.6
nvd
около 2 лет назад

A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource may consume is being processed (deserialized) prior to the security constraints being evaluated and applied. This does not happen with configuration based security.

EPSS

Процентиль: 69%
0.00601
Низкий

8.8 High

CVSS4

8.6 High

CVSS3

Дефекты

CWE-280
CWE-502
CWE-755