Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-2974

Опубликовано: 29 июн. 2023
Источник: redhat
CVSS3: 6.5

Описание

A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force the selection of the weaker supported TLS protocol.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Quarkusquarkus-vertx-httpAffected
Red Hat build of Quarkus 2.13.8.Finalio.quarkus/quarkus-grpcFixedRHSA-2023:380929.06.2023
Red Hat build of Quarkus 2.13.8.Finalio.quarkus/quarkus-vertx-httpFixedRHSA-2023:380929.06.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-757
https://bugzilla.redhat.com/show_bug.cgi?id=2211026quarkus-core: TLS protocol configured with quarkus.http.ssl.protocols is not enforced, client can enforce weaker supported TLS protocol

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
около 3 лет назад

A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force the selection of the weaker supported TLS protocol.

CVSS3: 6.5
github
около 3 лет назад

quarkus-core vulnerable to client driven TLS cipher downgrading

CVSS3: 6.5
fstec
больше 3 лет назад

Уязвимость реализации протокола TLS Java-фреймворка Quarkus, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

6.5 Medium

CVSS3