Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-0044

Опубликовано: 04 янв. 2023
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

If the Quarkus Form Authentication session cookie Path attribute is set to / then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented with the Quarkus CSRF Prevention feature.

A flaw was found in Quarkus. If the Quarkus Form Authentication session cookie Path attribute is set to /, then a cross-site attack may be initiated, which might lead to information disclosure.

Меры по смягчению последствий

This attack can be prevented with the Quarkus CSRF Prevention feature.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2quarkus-vertx-httpNot affected
Red Hat build of Apicurio Registry 2quarkus-vertx-httpNot affected
Red Hat build of Debezium 1quarkus-vertx-httpNot affected
Red Hat build of Quarkusio.quarkus/quarkus-vertx-httpNot affected
Red Hat Fuse 7quarkus-vertx-httpNot affected
Red Hat Integration Camel K 1quarkus-vertx-httpNot affected
Red Hat Integration Camel Quarkus 1quarkus-vertx-httpNot affected
Red Hat JBoss Enterprise Application Platform 7quarkus-vertx-httpNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packquarkus-vertx-httpNot affected
Red Hat Process Automation 7quarkus-vertx-httpNot affected

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=2158081quarkus-vertx-http: a cross-site attack may be initiated which might lead to the Information Disclosure

EPSS

Процентиль: 30%
0.00109
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
почти 3 года назад

If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented with the Quarkus CSRF Prevention feature.

CVSS3: 6.1
github
почти 3 года назад

Cross-site Scripting in Quarkus

CVSS3: 6.1
fstec
около 3 лет назад

Уязвимость компонента Form Authentication Java-фреймворка Quarkus, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

EPSS

Процентиль: 30%
0.00109
Низкий

5.3 Medium

CVSS3