Quarkus: http security policy bypass
Summary
| CVE | CVE-2023-4853 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-20 10:15:14 UTC |
| Updated | 2026-08-04 18:16:39 UTC |
| Description | A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service. |
Risk And Classification
Primary CVSS: v3.1 8.1 HIGH from [email protected]
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-148 | CWE-863 | CWE-148 Improper Neutralization of Input Leaders
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 8.1 | HIGH | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | [email protected] | Secondary | 8.1 | HIGH | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 8.1 | HIGH | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Red Hat | Openshift Serverless 1 On RHEL 8 | unaffected 0:1.9.2-3.el8 * rpm | Not specified |
| CNA | Red Hat | Red Hat Build Of OptaPlanner 8 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Build Of Quarkus 2.13.8.SP2 | unaffected 2.13.8.Final-redhat-00005 * rpm | Not specified |
| CNA | Red Hat | Red Hat Build Of Quarkus 2.13.8.SP2 | unaffected 2.13.8.Final-redhat-00005 * rpm | Not specified |
| CNA | Red Hat | Red Hat Build Of Quarkus 2.13.8.SP2 | unaffected 2.13.8.Final-redhat-00005 * rpm | Not specified |
| CNA | Red Hat | Red Hat Camel Extensions For Quarkus 2.13.3-1 | Not specified | Not specified |
| CNA | Red Hat | Red Hat OpenShift Serverless 1.30 | unaffected 1.9.2-3 * rpm | Not specified |
| CNA | Red Hat | Red Hat OpenShift Serverless 1.30 | unaffected 1.30.1-1 * rpm | Not specified |
| CNA | Red Hat | Red Hat OpenShift Serverless 1.30 | unaffected 1.30.1-1 * rpm | Not specified |
| CNA | Red Hat | Red Hat OpenShift Serverless 1.30 | unaffected 1.9.2-3 * rpm | Not specified |
| CNA | Red Hat | Red Hat OpenShift Serverless 1.30 | unaffected 1.30.1-1 * rpm | Not specified |
| CNA | Red Hat | Red Hat OpenShift Serverless 1.30 | unaffected 1.30.1-1 * rpm | Not specified |
| CNA | Red Hat | Red Hat OpenShift Serverless 1.30 | unaffected 1.30.1-1 * rpm | Not specified |
| CNA | Red Hat | Red Hat OpenShift Serverless 1.30 | unaffected 1.30.0-5 * rpm | Not specified |
| CNA | Red Hat | Red Hat OpenShift Serverless 1.30 | unaffected 1.30.0-6 * rpm | Not specified |
| CNA | Red Hat | Red Hat OpenShift Serverless 1.30 | unaffected 1.30.0-6 * rpm | Not specified |
| CNA | Red Hat | RHEL-8 Based Middleware Containers | unaffected 7.13.4-3 * rpm | Not specified |
| CNA | Red Hat | RHEL-8 Based Middleware Containers | unaffected 7.13.4-2 * rpm | Not specified |
| CNA | Red Hat | RHEL-8 Based Middleware Containers | unaffected 7.13.4-2 * rpm | Not specified |
| CNA | Red Hat | RHEL-8 Based Middleware Containers | unaffected 7.13.4-3 * rpm | Not specified |
| CNA | Red Hat | RHEL-8 Based Middleware Containers | unaffected 7.13.4-3 * rpm | Not specified |
| CNA | Red Hat | RHINT Camel-K-1.10.2 | Not specified | Not specified |
| CNA | Red Hat | RHINT Service Registry 2.5.4 GA | Not specified | Not specified |
| CNA | Red Hat | RHPAM 7.13.4 Async | Not specified | Not specified |
| CNA | Red Hat | Red Hat Build Of Quarkus | Not specified | Not specified |
| CNA | Red Hat | Red Hat Build Of Quarkus | Not specified | Not specified |
| CNA | Red Hat | Red Hat Process Automation 7 | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| RHSB-2023-002 Quarkus Security Policy Bypass - Quarkus - (CVE-2023-4853) - Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Exploit, Mitigation, Technical Description, Vendor Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Vendor Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Vendor Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Vendor Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Vendor Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Vendor Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Vendor Advisory |
| cve-details | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Mitigation, Vendor Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Vendor Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Vendor Advisory |
| access.redhat.com/errata/RHSA-2023:7653 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Vendor Advisory |
| 2238034 – (CVE-2023-4853) CVE-2023-4853 quarkus: HTTP security policy bypass | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2023-09-08T00:00:00.000Z | Reported to Red Hat. |
| CNA | 2023-09-08T00:00:00.000Z | Made public. |
Workarounds
CNA: Use a ‘deny’ wildcard for base paths, then authenticate specifics within that: Examples: ``` deny: /* authenticated: /services/* ``` or ``` deny: /services/* roles-allowed: /services/rbac/* ``` NOTE: Products are only vulnerable if they use (or allow use of) path-based HTTP policy configuration. Products may also be affected–shipping the component in question–without being vulnerable (“affected at reduced impact”). See https://access.redhat.com/security/vulnerabilities/RHSB-2023-002 for more detailed mitigations.
Legacy QID Mappings
- 995376 Java (Maven) Security Update for io.quarkus:quarkus-csrf-reactive (GHSA-4f4r-wgv2-jjvg)