Information disclosure in Quarkus - CVE-2023-0044

 

Information disclosure in Quarkus - CVE-2023-0044

Published: February 16, 2023


Vulnerability identifier: #VU72324
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-0044
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists if Quarkus Form Authentication session cookie Path attribute is set to "/". A remote attacker can perform a cross-site attack and obtain sensitive information from the cookie. The vulnerability affects Vert.x HTTP component.


Affected software

Quarkus
IBM Cloud Pak for Watson AIOps
Dell Data Protection Central
Red Hat build of Quarkus

How to mitigate CVE-2023-0044

Install updates from vendor's website.

Quarkus - update to 2.13.7
Red Hat build of Quarkus - addressed in versions 2.7.7, 2.13.7
Dell Data Protection Central - update to 19.11.0-2

External References

Related Security Bulletins