CVE-2023-4853CWE-148CWE-863broken-access-control

CVE-2023-4853

High · published September 20, 2023

CVSS v3.1
8.1
EPSS
1%
Percentile
66.5
In the wild
Unconfirmed
What it is

A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.

The record
Technical detail
CVSS v3.1
8.1 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.01215 · 66.5th percentile
Weaknesses
CWE-148 · Improper Neutralization of Input Leaders; CWE-863 · Incorrect Authorization
Published
2023-09-20T14:15Z
Affected products (17)
ProductVersionsFixed in
quarkus/quarkus< 2.16.112.16.11
quarkus/quarkus≥ 3.2.0, < 3.2.63.2.6
quarkus/quarkus≥ 3.3.0, < 3.3.33.3.3
redhat/build_of_optaplannerall versions
redhat/build_of_quarkus≥ 2.13.0, < 2.13.82.13.8
redhat/decision_managerall versions
redhat/integration_camel_k< 1.10.21.10.2
redhat/integration_camel_quarkusall versions
redhat/integration_service_registryall versions
redhat/jboss_middlewareall versions
redhat/jboss_middleware_text-only_advisoriesall versions
redhat/openshift_serverlessall versions
redhat/openshift_serverlessall versions
redhat/process_automation_managerall versions
redhat/openshift_container_platformall versions
redhat/openshift_container_platformall versions
redhat/openshift_container_platformall versions
References (24)
https://access.redhat.com/errata/RHSA-2023:5170 · [email protected]https://access.redhat.com/errata/RHSA-2023:5310 · [email protected]https://access.redhat.com/errata/RHSA-2023:5337 · [email protected]https://access.redhat.com/errata/RHSA-2023:5446 · [email protected]https://access.redhat.com/errata/RHSA-2023:5479 · [email protected]https://access.redhat.com/errata/RHSA-2023:5480 · [email protected]https://access.redhat.com/errata/RHSA-2023:6107 · [email protected]https://access.redhat.com/errata/RHSA-2023:6112 · [email protected]https://access.redhat.com/errata/RHSA-2023:7653 · [email protected]https://access.redhat.com/security/cve/CVE-2023-4853 · [email protected]https://access.redhat.com/security/vulnerabilities/RHSB-2023-002 · [email protected]https://bugzilla.redhat.com/show_bug.cgi?id=2238034 · [email protected]https://access.redhat.com/errata/RHSA-2023:5170 · af854a3a-2127-422b-91ae-364da2661108https://access.redhat.com/errata/RHSA-2023:5310 · af854a3a-2127-422b-91ae-364da2661108https://access.redhat.com/errata/RHSA-2023:5337 · af854a3a-2127-422b-91ae-364da2661108https://access.redhat.com/errata/RHSA-2023:5446 · af854a3a-2127-422b-91ae-364da2661108https://access.redhat.com/errata/RHSA-2023:5479 · af854a3a-2127-422b-91ae-364da2661108https://access.redhat.com/errata/RHSA-2023:5480 · af854a3a-2127-422b-91ae-364da2661108https://access.redhat.com/errata/RHSA-2023:6107 · af854a3a-2127-422b-91ae-364da2661108https://access.redhat.com/errata/RHSA-2023:6112 · af854a3a-2127-422b-91ae-364da2661108https://access.redhat.com/errata/RHSA-2023:7653 · af854a3a-2127-422b-91ae-364da2661108https://access.redhat.com/security/cve/CVE-2023-4853 · af854a3a-2127-422b-91ae-364da2661108https://access.redhat.com/security/vulnerabilities/RHSB-2023-002 · af854a3a-2127-422b-91ae-364da2661108https://bugzilla.redhat.com/show_bug.cgi?id=2238034 · af854a3a-2127-422b-91ae-364da2661108
EPSS history
Timeline
  • 20 SEP 09:47Z
    Quarkus: http security policy bypass
    cvelistv5