Skip to main content

Vendor/product archive

redhat / build_of_quarkus CVEs

Beta · best-effort

20 CVEs tagged to redhat / build_of_quarkus1 Critical, 8 High, 11 Medium, 0 Low, 0 Unrated.

CVE-2023-6394

Published Dec 9, 2023

A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the requ…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6393

Published Dec 6, 2023

A flaw was found in the Quarkus Cache Runtime. When request processing utilizes a Uni cached using @CacheResult and the cached Uni reuses the initial "completion" context, the pro…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2974

Published Jul 4, 2023

A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0044

Published Feb 23, 2023

If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Information Disclosure. This attac…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4492

Published Feb 23, 2023

The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by def…

CVSS 7.5 · High

CVE-2022-4116

Published Nov 22, 2022

A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-1259

Published Aug 31, 2022

A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exi…

CVSS 7.5 · High

CVE-2021-4178

Published Aug 24, 2022

A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allo…

CVSS 6.7 · Medium

CVE-2021-3536

Published May 20, 2021

A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, lead…

CVSS 4.8 · Medium

CVE-2021-20218

Published Mar 16, 2021

A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client…

CVSS 7.4 · High

CVE-2019-14900

Published Jul 6, 2020

A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals…

CVSS 6.5 · Medium
Showing 1-20 of 20 CVEsPage 1 of 1