Improper Authorization in Red Hat build of Quarkus - CVE-2023-5675
Published: January 25, 2024
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to the application.
The vulnerability exists due to improper enforcement of authorization when enabled by either "quarkus.security.jaxrs.deny-unannotated-endpoints" or "quarkus.security.jaxrs.default-roles-allowed" properties for RestEasy Classic or Reactive JAX-RS endpoints using the annotation processor. A remote attacker can gain unauthorized access to the application.
Affected software
IBM Cloud Pak for Business Automation
Business Automation Insights
How to mitigate CVE-2023-5675
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.31, 23.0.2.3
Business Automation Insights - update to 23.0.2.0.2