Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-6393

Опубликовано: 06 дек. 2023
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

A flaw was found in the Quarkus Cache Runtime. When request processing utilizes a Uni cached using @CacheResult and the cached Uni reuses the initial "completion" context, the processing switches to the cached Uni instead of the request context. This is a problem if the cached Uni context contains sensitive information, and could allow a malicious user to benefit from a POST request returning the response that is meant for another user, gaining access to sensitive data.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:build_of_quarkus:-:*:*:*:*:*:*:*

EPSS

Процентиль: 36%
0.00154
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.3
redhat
около 2 лет назад

A flaw was found in the Quarkus Cache Runtime. When request processing utilizes a Uni cached using @CacheResult and the cached Uni reuses the initial "completion" context, the processing switches to the cached Uni instead of the request context. This is a problem if the cached Uni context contains sensitive information, and could allow a malicious user to benefit from a POST request returning the response that is meant for another user, gaining access to sensitive data.

CVSS3: 5.3
github
около 2 лет назад

Quarkus Cache Runtime exposes sensitive information to an unauthorized actor

EPSS

Процентиль: 36%
0.00154
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
NVD-CWE-noinfo