First published: Wed Aug 31 2022(Updated: )
It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavior.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Quarkus Quarkus | >=2.10.0<2.10.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-2466.
The severity of CVE-2022-2466 is critical with a severity value of 9.8.
Quarkus versions 2.10.0 to 2.10.4 are affected by CVE-2022-2466.
CVE-2022-2466 may lead to unpredictable behavior due to the failure to terminate HTTP requests header context.
The fix for CVE-2022-2466 is not mentioned in the referenced source. Please refer to official Quarkus documentation or contact the vendor for more information on available fixes.