SB2023120534 - Information disclosure in Quarkus OIDC
Published: December 5, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cleartext transmission of sensitive information (CVE-ID: CVE-2023-1584)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an insecure HTTP protocol is used. A remote attacker can gain access to potentially sensitive information.
Remediation
Install update from vendor's website.