First published: Wed Jan 04 2023(Updated: )
A flaw was found in Quarkus. If the Quarkus Form Authentication session cookie Path attribute is set to `/`, then a cross-site attack may be initiated, which might lead to information disclosure.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Quarkus Quarkus | <2.13.7 | |
Redhat Build Of Quarkus | ||
redhat/quarkus-vertx-http | <2.13.7 | 2.13.7 |
This attack can be prevented with the Quarkus CSRF Prevention feature.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this flaw is CVE-2023-0044.
CVE-2023-0044 has a severity level of medium.
This vulnerability affects Quarkus if the Quarkus Form Authentication session cookie Path attribute is set to '/'.
The potential risk of this vulnerability is cross-site attack which may lead to information disclosure.
The Quarkus CSRF Prevention feature can prevent the cross-site attack and mitigate the risk of information disclosure.