Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-6394

Опубликовано: 08 дек. 2023
Источник: redhat
CVSS3: 7.4

Описание

A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.

Дополнительная информация

Статус:

Important
Дефект:
CWE-696->CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=2252197quarkus: GraphQL operations over WebSockets bypass

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
nvd
около 2 лет назад

A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.

CVSS3: 7.4
github
около 2 лет назад

Authorization bypass in Quarkus

CVSS3: 7.4
fstec
около 2 лет назад

Уязвимость технологии WebSocket Java-фреймворка Quarkus, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и повысить свои привилегии

7.4 High

CVSS3