cbcvebase.
CVE-2023-4853
published 2023-09-20

CVE-2023-4853: A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in…

high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.

Affected

14 ranges
VendorProductVersion rangeFixed in
quarkusquarkus< 2.16.112.16.11
quarkusquarkus>= 3.2.0 < 3.2.63.2.6
quarkusquarkus>= 3.3.0 < 3.3.33.3.3
redhatbuild_of_optaplanner
redhatbuild_of_quarkus>= 2.13.0 < 2.13.82.13.8
redhatdecision_manager
redhatintegration_camel_k< 1.10.21.10.2
redhatjboss_middleware
redhatjboss_middleware_text-only_advisories
redhatopenshift_container_platform
redhatopenshift_container_platform
redhatopenshift_container_platform
redhatopenshift_serverless
redhatprocess_automation_manager