Algorithm Downgrade in Red Hat build of Quarkus - CVE-2023-2974
Published: January 30, 2024
Vulnerability identifier: #VU85904
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-2974
CWE-ID: CWE-757
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to modify data on the system.
The vulnerability exists due to TLS protocol configured with quarkus.http.ssl.protocols is not enforced. A remote user can client can force the selection of the weaker supported TLS protocol to modify data on the system.
Affected software
Red Hat build of Quarkus
IBM Cloud Pak for Watson AIOps
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2023-2974
Install updates from vendor's website.
Red Hat build of Quarkus - update to 2.13.8
IBM Cloud Pak for Watson AIOps - update to 4.2.0
IBM Cloud Pak for Watson AIOps - update to 4.2.0