Логотип exploitDog
bind:CVE-2023-5675
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-5675

Количество 3

Количество 3

redhat логотип

CVE-2023-5675

почти 2 года назад

A flaw was found in Quarkus. When a Quarkus RestEasy Classic or Reactive JAX-RS endpoint has its methods declared in the abstract Java class or customized by Quarkus extensions using the annotation processor, the authorization of these methods will not be enforced if it is enabled by either 'quarkus.security.jaxrs.deny-unannotated-endpoints' or 'quarkus.security.jaxrs.default-roles-allowed' properties.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-5675

больше 1 года назад

A flaw was found in Quarkus. When a Quarkus RestEasy Classic or Reactive JAX-RS endpoint has its methods declared in the abstract Java class or customized by Quarkus extensions using the annotation processor, the authorization of these methods will not be enforced if it is enabled by either 'quarkus.security.jaxrs.deny-unannotated-endpoints' or 'quarkus.security.jaxrs.default-roles-allowed' properties.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-25w4-hfqg-4r52

больше 1 года назад

Quarkus: authorization flaw in quarkus resteasy reactive and classic

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2023-5675

A flaw was found in Quarkus. When a Quarkus RestEasy Classic or Reactive JAX-RS endpoint has its methods declared in the abstract Java class or customized by Quarkus extensions using the annotation processor, the authorization of these methods will not be enforced if it is enabled by either 'quarkus.security.jaxrs.deny-unannotated-endpoints' or 'quarkus.security.jaxrs.default-roles-allowed' properties.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2023-5675

A flaw was found in Quarkus. When a Quarkus RestEasy Classic or Reactive JAX-RS endpoint has its methods declared in the abstract Java class or customized by Quarkus extensions using the annotation processor, the authorization of these methods will not be enforced if it is enabled by either 'quarkus.security.jaxrs.deny-unannotated-endpoints' or 'quarkus.security.jaxrs.default-roles-allowed' properties.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-25w4-hfqg-4r52

Quarkus: authorization flaw in quarkus resteasy reactive and classic

CVSS3: 6.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу