Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-0981

Опубликовано: 03 фев. 2022
Источник: redhat
CVSS3: 7.6
EPSS Низкий

Описание

A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another in RestEasy Reactive. This flaw allows a low-privileged user to perform operations on the database with a different set of privileges than intended.

Отчет

CodeReady Studio is no longer supported and therefore this flaw will not be addressed in CodeReady Studio. Please see https://developers.redhat.com/articles/2022/04/18/announcement-red-hat-codeready-studio-reaches-end-life for more information.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat CodeReady Studio 12quarkusOut of support scope
Red Hat Integration Camel K 1quarkusAffected
Red Hat build of Quarkus 2.7.5quarkusFixedRHSA-2022:462318.05.2022
RHINT Camel-Q 2.7quarkusFixedRHSA-2022:560619.07.2022
RHINT Service Registry 2.3.0 GAquarkusFixedRHSA-2022:683506.10.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2062520quarkus: privilege escalation vulnerability with RestEasy Reactive scope leakage in Quarkus

EPSS

Процентиль: 47%
0.00241
Низкий

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
почти 4 года назад

A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another in RestEasy Reactive. This flaw allows a low-privileged user to perform operations on the database with a different set of privileges than intended.

CVSS3: 8.8
github
почти 4 года назад

A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another in RestEasy Reactive. This flaw allows a low-privileged user to perform operations on the database with a different set of privileges than intended.

EPSS

Процентиль: 47%
0.00241
Низкий

7.6 High

CVSS3