CVE-2023-2974
published 2023-07-04CVE-2023-2974: A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and…
PriorityP342high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.88%
55.0th percentile
A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force the selection of the weaker supported TLS protocol.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | build_of_quarkus | < 2.13.8 | 2.13.8 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
quarkus-core: TLS protocol configured with quarkus.http.ssl.protocols is not enforced, client can enforce weaker supported TLS protocol
vendor_redhat·2023-06-29·CVSS 6.5
CVE-2023-2974 [MEDIUM] CWE-757 quarkus-core: TLS protocol configured with quarkus.http.ssl.protocols is not enforced, client can enforce weaker supported TLS protocol
quarkus-core: TLS protocol configured with quarkus.http.ssl.protocols is not enforced, client can enforce weaker supported TLS protocol
A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force the selection of the weaker supported TLS protocol.
A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force the selection of the weaker supported TLS protocol.
OSV
quarkus-core vulnerable to client driven TLS cipher downgrading
osv·2023-07-04
CVE-2023-2974 [MEDIUM] quarkus-core vulnerable to client driven TLS cipher downgrading
quarkus-core vulnerable to client driven TLS cipher downgrading
A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force the selection of the weaker supported TLS protocol.
GHSA
quarkus-core vulnerable to client driven TLS cipher downgrading
ghsa·2023-07-04
CVE-2023-2974 [MEDIUM] quarkus-core vulnerable to client driven TLS cipher downgrading
quarkus-core vulnerable to client driven TLS cipher downgrading
A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force the selection of the weaker supported TLS protocol.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:3809https://access.redhat.com/security/cve/CVE-2023-2974https://bugzilla.redhat.com/show_bug.cgi?id=2211026https://access.redhat.com/errata/RHSA-2023:3809https://access.redhat.com/security/cve/CVE-2023-2974https://bugzilla.redhat.com/show_bug.cgi?id=2211026
2023-07-04
Published