Improper Authorization in Red Hat build of Quarkus - CVE-2023-5675
Published: January 25, 2024
Red Hat build of Quarkus
Red Hat Inc.
Description
The vulnerability allows a remote attacker to gain unauthorized access to the application.
The vulnerability exists due to improper enforcement of authorization when enabled by either "quarkus.security.jaxrs.deny-unannotated-endpoints" or "quarkus.security.jaxrs.default-roles-allowed" properties for RestEasy Classic or Reactive JAX-RS endpoints using the annotation processor. A remote attacker can gain unauthorized access to the application.