Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mvc8-6ffp-jrx5

Опубликовано: 09 дек. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.4

Описание

Authorization bypass in Quarkus

A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.

Пакеты

Наименование

io.quarkus:quarkus-smallrye-graphql-client

maven
Затронутые версииВерсия исправления

>= 2.14.0, < 3.5.3

3.5.3

Наименование

io.quarkus:quarkus-smallrye-graphql-client

maven
Затронутые версииВерсия исправления

< 2.13.9.Final

2.13.9.Final

EPSS

Процентиль: 55%
0.00814
Низкий

7.4 High

CVSS3

Дефекты

CWE-551
CWE-696
CWE-862

Связанные уязвимости

CVSS3: 7.4
redhat
почти 3 года назад

A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.

CVSS3: 7.4
nvd
почти 3 года назад

A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.

CVSS3: 7.4
fstec
почти 3 года назад

Уязвимость технологии WebSocket Java-фреймворка Quarkus, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и повысить свои привилегии

EPSS

Процентиль: 55%
0.00814
Низкий

7.4 High

CVSS3

Дефекты

CWE-551
CWE-696
CWE-862