Security features bypass in Red Hat build of Quarkus - CVE-2023-4853

 

Security features bypass in Red Hat build of Quarkus - CVE-2023-4853

Published: September 15, 2023


Vulnerability identifier: #VU80813
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-4853
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to implemented HTTP security policies do not correctly sanitize certain character permutations, which may result in incorrect evaluation of permissions. A remote attacker can bypass the security policy altogether and gain unauthorized access to endpoints or perform a denial of service (DoS) attack.


Affected software

Red Hat build of Quarkus
Red Hat Integration Camel-K
Red Hat Integration Camel Extensions for Quarkus
IBM Automation Decision Services
Red Hat Integration - Service Registry
Red Hat Build of OptaPlanner for Quarkus
IBM Cloud Pak for Business Automation
Event Processing
IBM Business Automation Manager Open Editions
IBM Event Endpoint Management
Dell Data Protection Central
Red Hat OpenShift Serverless
OpenShift Serverless Client
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
openshift-serverless-clients (Red Hat package)

How to mitigate CVE-2023-4853

Install updates from vendor's website.

Red Hat build of Quarkus - update to 2.13.8
Event Processing - update to 1.0.4
Red Hat OpenShift Serverless - update to 1.30.1
Red Hat Integration Camel-K - update to 1.10.2
OpenShift Serverless Client - update to 1.30.1
Red Hat Integration Camel Extensions for Quarkus - update to 2.13.3-1
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - addressed in versions 7.13.4, 7.13.4 SP1
IBM Business Automation Manager Open Editions - addressed in versions 8.0.4, 8.0.4 IF001
IBM Event Endpoint Management - update to 11.0.5
IBM Automation Decision Services - update to 23.0.1 IF005
openshift-serverless-clients (Red Hat package) - update to 1.9.2-3.el8
Red Hat Integration - Service Registry - update to 2.5.4
Red Hat Build of OptaPlanner for Quarkus - update to 8.38.0
Dell Data Protection Central - update to 19.11.0-2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.27, 23.0.1.5

External References

Related Security Bulletins