First published: Thu Feb 03 2022(Updated: )
A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another in RestEasy Reactive. This flaw allows a low-privileged user to perform operations on the database with a different set of privileges than intended.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/quarkus | <2.7.1. | 2.7.1. |
Quarkus Quarkus | <2.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-0981 is a vulnerability in Quarkus that allows a low-privileged user to perform unauthorized operations on the database.
CVE-2022-0981 has a severity value of 7, which is considered high.
CVE-2022-0981 affects Quarkus versions up to and excluding 2.7.1.
To fix CVE-2022-0981, update Quarkus to version 2.7.1 or later.
You can find more information about CVE-2022-0981 in the following references: [GitHub PR](https://github.com/quarkusio/quarkus/pull/23397), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2022:4623), [Red Hat CVE Database](https://access.redhat.com/security/cve/cve-2022-0981).