Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-1247

Опубликовано: 12 фев. 2025
Источник: redhat
CVSS3: 8.3
EPSS Низкий

Описание

A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.

Отчет

This vulnerability marked as important severity rather than moderate because it leads to cross-request data leakage, which can compromise the confidentiality and integrity of user interactions. In a concurrent environment, multiple requests being served by a single, shared instance of an endpoint class means that sensitive request data—such as authentication headers, cookies, or form parameters—can be inadvertently exposed to other users. This violates fundamental HTTP request isolation principles, potentially leading to session hijacking, unauthorized access, or privilege escalation.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-488
https://bugzilla.redhat.com/show_bug.cgi?id=2345172io.quarkus:quarkus-rest: Quarkus REST Endpoint Request Parameter Leakage Due to Shared Instance

EPSS

Процентиль: 28%
0.00101
Низкий

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
nvd
11 месяцев назад

A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.

CVSS3: 8.3
github
11 месяцев назад

Quarkus REST Endpoint Request Parameter Leakage Due to Shared Instance

EPSS

Процентиль: 28%
0.00101
Низкий

8.3 High

CVSS3