Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2023-6394

почти 3 года назад

A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2023-6394

почти 3 года назад

A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-mvc8-6ffp-jrx5

почти 3 года назад

Authorization bypass in Quarkus

CVSS3: 7.4
EPSS: Низкий
fstec логотип

BDU:2023-08669

почти 3 года назад

Уязвимость технологии WebSocket Java-фреймворка Quarkus, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и повысить свои привилегии

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2023-6394

A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.

CVSS3: 7.4
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-6394

A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.

CVSS3: 7.4
1%
Низкий
почти 3 года назад
github логотип
GHSA-mvc8-6ffp-jrx5

Authorization bypass in Quarkus

CVSS3: 7.4
1%
Низкий
почти 3 года назад
fstec логотип
BDU:2023-08669

Уязвимость технологии WebSocket Java-фреймворка Quarkus, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и повысить свои привилегии

CVSS3: 7.4
1%
Низкий
почти 3 года назад

Уязвимостей на страницу