Описание
A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force the selection of the weaker supported TLS protocol.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Quarkus | quarkus-vertx-http | Affected | ||
| Red Hat build of Quarkus 2.13.8.Final | io.quarkus/quarkus-grpc | Fixed | RHSA-2023:3809 | 29.06.2023 |
| Red Hat build of Quarkus 2.13.8.Final | io.quarkus/quarkus-vertx-http | Fixed | RHSA-2023:3809 | 29.06.2023 |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-757
https://bugzilla.redhat.com/show_bug.cgi?id=2211026quarkus-core: TLS protocol configured with quarkus.http.ssl.protocols is not enforced, client can enforce weaker supported TLS protocol
6.5 Medium
CVSS3
Связанные уязвимости
CVSS3: 6.5
nvd
около 3 лет назад
A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force the selection of the weaker supported TLS protocol.
CVSS3: 6.5
github
около 3 лет назад
quarkus-core vulnerable to client driven TLS cipher downgrading
CVSS3: 6.5
fstec
больше 3 лет назад
Уязвимость реализации протокола TLS Java-фреймворка Quarkus, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
6.5 Medium
CVSS3