CVE-2023-4853
Summary
| CVE | CVE-2023-4853 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-20 10:15:00 UTC |
| Updated | 2023-12-05 22:15:00 UTC |
| Description | A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service. |
Risk And Classification
Problem Types: CWE-863
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Quarkus | Quarkus | All | All | All | All |
| Application | Redhat | Build Of Optaplanner | 8.0 | All | All | All |
| Application | Redhat | Build Of Quarkus | All | All | All | All |
| Application | Redhat | Decision Manager | 7.0 | All | All | All |
| Application | Redhat | Integration Camel K | All | All | All | All |
| Application | Redhat | Integration Camel Quarkus | - | All | All | All |
| Application | Redhat | Integration Service Registry | - | All | All | All |
| Application | Redhat | Jboss Middleware | 1 | All | All | All |
| Application | Redhat | Openshift Serverless | - | All | All | All |
| Application | Redhat | Openshift Serverless | 1.0 | All | All | All |
| Application | Redhat | Process Automation Manager | 7.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat | MISC | access.redhat.com | |
| RHSB-2023-002 Quarkus Security Policy Bypass - Quarkus - (CVE-2023-4853) - Red Hat Customer Portal | MISC | access.redhat.com | |
| Red Hat | MISC | access.redhat.com | |
| Red Hat | MISC | access.redhat.com | |
| Red Hat | MISC | access.redhat.com | |
| RHSA-2023:7653 | access.redhat.com | ||
| Red Hat | MISC | access.redhat.com | |
| Red Hat | MISC | access.redhat.com | |
| Red Hat | MISC | access.redhat.com | |
| cve-details | MISC | access.redhat.com | |
| 2238034 – (CVE-2023-4853) CVE-2023-4853 quarkus: HTTP security policy bypass | MISC | bugzilla.redhat.com | |
| Red Hat | MISC | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995376 Java (Maven) Security Update for io.quarkus:quarkus-csrf-reactive (GHSA-4f4r-wgv2-jjvg)