Логотип exploitDog
bind:CVE-2023-1584
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-1584

Количество 3

Количество 3

redhat логотип

CVE-2023-1584

почти 3 года назад

A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an insecure HTTP protocol is used, which can allow attackers to access sensitive user data directly from the ID token or by using the access token to access user data from OIDC provider services. Please note that passwords are not stored in access tokens.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-1584

больше 2 лет назад

A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an insecure HTTP protocol is used, which can allow attackers to access sensitive user data directly from the ID token or by using the access token to access user data from OIDC provider services. Please note that passwords are not stored in access tokens.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-6hc9-cf8x-hf83

больше 2 лет назад

Quarkus OIDC can leak both ID and access tokens

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2023-1584

A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an insecure HTTP protocol is used, which can allow attackers to access sensitive user data directly from the ID token or by using the access token to access user data from OIDC provider services. Please note that passwords are not stored in access tokens.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-1584

A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an insecure HTTP protocol is used, which can allow attackers to access sensitive user data directly from the ID token or by using the access token to access user data from OIDC provider services. Please note that passwords are not stored in access tokens.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-6hc9-cf8x-hf83

Quarkus OIDC can leak both ID and access tokens

CVSS3: 7.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу