CVE-2023-4853
published 2023-09-20CVE-2023-4853: A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in…
PriorityP349high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
1.21%
65.1th percentile
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| quarkus | quarkus | < 2.16.11 | 2.16.11 |
| quarkus | quarkus | >= 3.2.0 < 3.2.6 | 3.2.6 |
| quarkus | quarkus | >= 3.3.0 < 3.3.3 | 3.3.3 |
| redhat | build_of_optaplanner | — | — |
| redhat | build_of_quarkus | >= 2.13.0 < 2.13.8 | 2.13.8 |
| redhat | decision_manager | — | — |
| redhat | integration_camel_k | < 1.10.2 | 1.10.2 |
| redhat | jboss_middleware | — | — |
| redhat | jboss_middleware_text-only_advisories | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_serverless | — | — |
| redhat | process_automation_manager | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Quarkus HTTP vulnerable to incorrect evaluation of permissions
ghsa·2023-09-20
CVE-2023-4853 [HIGH] CWE-148 Quarkus HTTP vulnerable to incorrect evaluation of permissions
Quarkus HTTP vulnerable to incorrect evaluation of permissions
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.
OSV
Quarkus HTTP vulnerable to incorrect evaluation of permissions
osv·2023-09-20
CVE-2023-4853 [HIGH] Quarkus HTTP vulnerable to incorrect evaluation of permissions
Quarkus HTTP vulnerable to incorrect evaluation of permissions
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.
Red Hat
quarkus: HTTP security policy bypass
vendor_redhat·2023-09-08·CVSS 8.1
CVE-2023-4853 [HIGH] CWE-148 quarkus: HTTP security policy bypass
quarkus: HTTP security policy bypass
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.
Mitigation: Use a ‘deny’ wildcard for base paths, then authenticate sp
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:5170https://access.redhat.com/errata/RHSA-2023:5310https://access.redhat.com/errata/RHSA-2023:5337https://access.redhat.com/errata/RHSA-2023:5446https://access.redhat.com/errata/RHSA-2023:5479https://access.redhat.com/errata/RHSA-2023:5480https://access.redhat.com/errata/RHSA-2023:6107https://access.redhat.com/errata/RHSA-2023:6112https://access.redhat.com/errata/RHSA-2023:7653https://access.redhat.com/security/cve/CVE-2023-4853https://access.redhat.com/security/vulnerabilities/RHSB-2023-002https://bugzilla.redhat.com/show_bug.cgi?id=2238034https://access.redhat.com/errata/RHSA-2023:5170https://access.redhat.com/errata/RHSA-2023:5310https://access.redhat.com/errata/RHSA-2023:5337https://access.redhat.com/errata/RHSA-2023:5446https://access.redhat.com/errata/RHSA-2023:5479https://access.redhat.com/errata/RHSA-2023:5480https://access.redhat.com/errata/RHSA-2023:6107https://access.redhat.com/errata/RHSA-2023:6112https://access.redhat.com/errata/RHSA-2023:7653https://access.redhat.com/security/cve/CVE-2023-4853https://access.redhat.com/security/vulnerabilities/RHSB-2023-002https://bugzilla.redhat.com/show_bug.cgi?id=2238034
2023-09-20
Published