Red Hat Build Of Quarkus 2.13.0 Text-only Edition

CPE Details

Red Hat Build Of Quarkus 2.13.0 Text-only Edition
2.13.0
2023-09-28
09h09 +00:00
2023-09-28
09h09 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:redhat:build_of_quarkus:2.13.0:*:*:*:text-only:*:*:*

Informations

Vendor

redhat

Product

build_of_quarkus

Version

2.13.0

Software Edition

text-only

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-4853 2023-09-20 09h47 +00:00 A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.
8.1
High
CVE-2023-2974 2023-07-04 13h24 +00:00 A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force the selection of the weaker supported TLS protocol.
8.1
High