Known Vulnerabilities for Build Of Quarkus by Redhat
Listed below are 10 of the newest known vulnerabilities associated with "Build Of Quarkus" by "Redhat".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-44487 json | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many stre... | 7.5 - HIGH | 2023-10-10 | 2024-02-02 |
| CVE-2023-4853 json | A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when acc... | 8.1 - HIGH | 2023-09-20 | 2023-12-05 |
| CVE-2023-2974 json | A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ss... | 8.1 - HIGH | 2023-07-04 | 2023-11-07 |
| CVE-2023-1664 json | A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled ... | 6.5 - MEDIUM | 2023-05-26 | 2023-06-03 |
| CVE-2023-1108 json | A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status u... | 7.5 - HIGH | 2023-09-14 | 2023-11-16 |
| CVE-2023-0044 json | If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated whic... | 6.1 - MEDIUM | 2023-02-23 | 2023-03-03 |
| CVE-2022-4492 json | The undertow client is not checking the server identity presented by the server certificate in https connections. This is a c... | 7.5 - HIGH | 2023-02-23 | 2023-03-24 |
| CVE-2022-4116 json | A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by loca... | 9.8 - CRITICAL | 2022-11-22 | 2023-08-08 |
| CVE-2022-1259 json | A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhe... | 7.5 - HIGH | 2022-08-31 | 2022-11-07 |
| CVE-2022-1011 json | A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows ... | 7.8 - HIGH | 2022-03-18 | 2022-10-12 |