Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mvc8-6ffp-jrx5

Опубликовано: 09 дек. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.4

Описание

Authorization bypass in Quarkus

A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.

Пакеты

Наименование

io.quarkus:quarkus-smallrye-graphql-client

maven
Затронутые версииВерсия исправления

>= 2.14.0, < 3.5.3

3.5.3

Наименование

io.quarkus:quarkus-smallrye-graphql-client

maven
Затронутые версииВерсия исправления

< 2.13.9.Final

2.13.9.Final

EPSS

Процентиль: 65%
0.00488
Низкий

7.4 High

CVSS3

Дефекты

CWE-696
CWE-862

Связанные уязвимости

CVSS3: 7.4
redhat
около 2 лет назад

A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.

CVSS3: 7.4
nvd
около 2 лет назад

A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.

CVSS3: 7.4
fstec
около 2 лет назад

Уязвимость технологии WebSocket Java-фреймворка Quarkus, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и повысить свои привилегии

EPSS

Процентиль: 65%
0.00488
Низкий

7.4 High

CVSS3

Дефекты

CWE-696
CWE-862