Algorithm Downgrade in Red Hat build of Quarkus - CVE-2023-2974

 

Algorithm Downgrade in Red Hat build of Quarkus - CVE-2023-2974

Published: January 30, 2024


Vulnerability identifier: #VU85904
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-2974
CWE-ID: CWE-757
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify data on the system.

The vulnerability exists due to TLS protocol configured with quarkus.http.ssl.protocols is not enforced. A remote user can client can force the selection of the weaker supported TLS protocol to modify data on the system.


Affected software

Red Hat build of Quarkus
IBM Cloud Pak for Watson AIOps

How to mitigate CVE-2023-2974

Install updates from vendor's website.

Red Hat build of Quarkus - update to 2.13.8
IBM Cloud Pak for Watson AIOps - update to 4.2.0

External References

Related Security Bulletins