Quarkus HTTP vulnerable to incorrect evaluation of permissions
High severity
GitHub Reviewed
Published
Sep 20, 2023
to the GitHub Advisory Database
•
Updated Dec 6, 2023
Package
Affected versions
< 2.16.11.Final
>= 3.0.0, < 3.2.6.Final
>= 3.3.0, < 3.3.3
Patched versions
2.16.11.Final
3.2.6.Final
3.3.3
< 2.16.11.Final
>= 3.0.0, < 3.2.6.Final
>= 3.3.0, < 3.3.3
2.16.11.Final
3.2.6.Final
3.3.3
< 2.16.11.Final
>= 3.0.0, < 3.2.6.Final
>= 3.3.0, < 3.3.3
2.16.11.Final
3.2.6.Final
3.3.3
< 2.16.11.Final
>= 3.0.0, < 3.2.6.Final
>= 3.3.0, < 3.3.3
2.16.11.Final
3.2.6.Final
3.3.3
Description
Published by the National Vulnerability Database
Sep 20, 2023
Published to the GitHub Advisory Database
Sep 20, 2023
Reviewed
Sep 21, 2023
Last updated
Dec 6, 2023
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.
References