CVE-2022-2466: Critical severity red hat quarkus vulnerability
Published Aug 31, 2022
·Updated
It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavior.
Affected Software
1 affected component
Quarkus Quarkus>=2.10.0<2.10.4
Event History
Aug 31, 2022
CVE Published
via MITRE·03:33 PM
Data Sourced
via MITRE·03:33 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-2466.
2
What is the severity of CVE-2022-2466?
The severity of CVE-2022-2466 is critical with a severity value of 9.8.
3
What software versions are affected by CVE-2022-2466?
Quarkus versions 2.10.0 to 2.10.4 are affected by CVE-2022-2466.
4
What is the impact of CVE-2022-2466?
CVE-2022-2466 may lead to unpredictable behavior due to the failure to terminate HTTP requests header context.
5
Is there a fix available for CVE-2022-2466?
The fix for CVE-2022-2466 is not mentioned in the referenced source. Please refer to official Quarkus documentation or contact the vendor for more information on available fixes.