Information disclosure in Quarkus - CVE-2023-0044
Published: February 16, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists if Quarkus Form Authentication session cookie Path attribute is set to "/". A remote attacker can perform a cross-site attack and obtain sensitive information from the cookie. The vulnerability affects Vert.x HTTP component.
Affected software
IBM Cloud Pak for Watson AIOps
Dell Data Protection Central
Red Hat build of Quarkus
How to mitigate CVE-2023-0044
Red Hat build of Quarkus - addressed in versions 2.7.7, 2.13.7
Dell Data Protection Central - update to 19.11.0-2