{"api_version":"1","generated_at":"2026-08-22T17:47:30+00:00","cve":"CVE-2025-1247","urls":{"html":"https://cve.report/CVE-2025-1247","api":"https://cve.report/api/cve/CVE-2025-1247.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-1247","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-1247"},"summary":{"title":"Io.quarkus:quarkus-rest: quarkus rest endpoint request parameter leakage due to shared instance","description":"A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.","state":"PUBLISHED","assigner":"redhat","published_at":"2025-02-13 14:16:18","updated_at":"2026-08-04 11:22:42"},"problem_types":["CWE-488","CWE-488 Exposure of Data Element to Wrong Session"],"metrics":[{"version":"3.1","source":"secalert@redhat.com","type":"Secondary","score":"8.3","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","baseScore":8.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"8.3","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":8.3,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","version":"3.1"}}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2025-1247","name":"https://access.redhat.com/security/cve/CVE-2025-1247","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/quarkusio/quarkus/issues/45789","name":"https://github.com/quarkusio/quarkus/issues/45789","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2025:1884","name":"https://access.redhat.com/errata/RHSA-2025:1884","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2025:2067","name":"https://access.redhat.com/errata/RHSA-2025:2067","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2025:1885","name":"https://access.redhat.com/errata/RHSA-2025:1885","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2345172","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2345172","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-1247","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-1247","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Red Hat","product":"Red Hat Build of Apache Camel 4.8 for Quarkus 3.15","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat build of Quarkus 3.15.3.SP1","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat build of Quarkus 3.8.6.SP3","version":"","platforms":[]}],"timeline":[{"source":"CNA","time":"2025-02-12T09:30:25.106Z","lang":"en","value":"Reported to Red Hat."},{"source":"CNA","time":"2025-02-12T00:00:00.000Z","lang":"en","value":"Made public."}],"solutions":[],"workarounds":[{"source":"CNA","title":"","value":"Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.","time":"","lang":"en"}],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2025","cve_id":"1247","cve":"CVE-2025-1247","epss":"0.007560000","percentile":"0.516620000","score_date":"2026-08-06","updated_at":"2026-08-07 00:14:20"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2025-1247","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2025-02-13T14:11:32.786242Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2025-02-13T14:11:38.780Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"collectionURL":"https://github.com/quarkusio/quarkus/","defaultStatus":"unaffected","packageName":"quarkus-rest","versions":[{"lessThan":"3.18.2","status":"affected","version":"0","versionType":"semver"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:camel_quarkus:3.15"],"defaultStatus":"unaffected","packageName":"quarkus-rest","product":"Red Hat Build of Apache Camel 4.8 for Quarkus 3.15","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:quarkus:3.15::el8"],"defaultStatus":"unaffected","packageName":"quarkus-rest","product":"Red Hat build of Quarkus 3.15.3.SP1","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:quarkus:3.8::el8"],"defaultStatus":"unaffected","packageName":"quarkus-rest","product":"Red Hat build of Quarkus 3.8.6.SP3","vendor":"Red Hat"}],"datePublic":"2025-02-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information."}],"metrics":[{"other":{"content":{"namespace":"https://access.redhat.com/security/updates/classification/","value":"Important"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":8.3,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-488","description":"Exposure of Data Element to Wrong Session","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-04T11:04:21.785Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"RHSA-2025:1884","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2025:1884"},{"name":"RHSA-2025:1885","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2025:1885"},{"name":"RHSA-2025:2067","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2025:2067"},{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2025-1247"},{"name":"RHBZ#2345172","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2345172"},{"url":"https://github.com/quarkusio/quarkus/issues/45789"}],"timeline":[{"lang":"en","time":"2025-02-12T09:30:25.106Z","value":"Reported to Red Hat."},{"lang":"en","time":"2025-02-12T00:00:00.000Z","value":"Made public."}],"title":"Io.quarkus:quarkus-rest: quarkus rest endpoint request parameter leakage due to shared instance","workarounds":[{"lang":"en","value":"Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability."}],"x_generator":{"engine":"cvelib 1.8.0"},"x_redhatCweChain":"CWE-488: Exposure of Data Element to Wrong Session"}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2025-1247","datePublished":"2025-02-13T13:26:26.992Z","dateReserved":"2025-02-12T09:43:11.716Z","dateUpdated":"2026-08-04T11:04:21.785Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2025-02-13 14:16:18","lastModifiedDate":"2026-08-04 11:22:42","problem_types":["CWE-488","CWE-488 Exposure of Data Element to Wrong Session"],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","baseScore":8.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":5.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-13T14:11:32.786242Z","id":"CVE-2025-1247","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"1247","Ordinal":"1","Title":"Io.quarkus:quarkus-rest: quarkus rest endpoint request parameter","CVE":"CVE-2025-1247","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"1247","Ordinal":"1","NoteData":"A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.","Type":"Description","Title":"Io.quarkus:quarkus-rest: quarkus rest endpoint request parameter"}]}}}