Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mwhw-6p27-4crc

Опубликовано: 01 сент. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Quarkus does not terminate HTTP requests header context

Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavior. This issue was fixed in version 2.10.4Final.

Пакеты

Наименование

io.quarkus:quarkus-core-parent

maven
Затронутые версииВерсия исправления

>= 2.10.0, < 2.10.4

2.10.4

EPSS

Процентиль: 94%
0.12221
Средний

9.8 Critical

CVSS3

Дефекты

CWE-444

Связанные уязвимости

CVSS3: 5.3
redhat
больше 3 лет назад

It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavior.

CVSS3: 9.8
nvd
больше 3 лет назад

It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavior.

EPSS

Процентиль: 94%
0.12221
Средний

9.8 Critical

CVSS3

Дефекты

CWE-444