Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-1584

Опубликовано: 04 окт. 2023
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an insecure HTTP protocol is used, which can allow attackers to access sensitive user data directly from the ID token or by using the access token to access user data from OIDC provider services. Please note that passwords are not stored in access tokens.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:*
Версия до 2.13.8 (исключая)

EPSS

Процентиль: 52%
0.00291
Низкий

7.5 High

CVSS3

Дефекты

CWE-200
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.5
redhat
почти 3 года назад

A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an insecure HTTP protocol is used, which can allow attackers to access sensitive user data directly from the ID token or by using the access token to access user data from OIDC provider services. Please note that passwords are not stored in access tokens.

CVSS3: 7.5
github
больше 2 лет назад

Quarkus OIDC can leak both ID and access tokens

EPSS

Процентиль: 52%
0.00291
Низкий

7.5 High

CVSS3

Дефекты

CWE-200
NVD-CWE-noinfo