CVE-2023-5675 describes a security bypass vulnerability in Quarkus, specifically impacting RestEasy Classic or Reactive JAX-RS endpoints. When methods are declared in an abstract Java class or customized by Quarkus extensions, authorization configured via 'quarkus.security.jaxrs.deny-unannotated-endpoints' or 'quarkus.security.jaxrs.default-roles-allowed' properties will not be enforced. This medium-severity vulnerability (CVSS 6.5) has a low attack complexity and could lead to unauthorized access to sensitive information or functionality (CWE-285). There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE match | cpe:2.3:a:redhat:openshift_serverless:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Quarkus: authorization flaw in quarkus resteasy reactive and classic
Apr 25, 2024quarkus: Authorization flaw in Quarkus RestEasy Reactive and Classic when "quarkus.security.jaxrs.deny-unannotated-endpoints" or "quarkus.security.jaxrs.default-roles-allowed" properties are used.
Jan 24, 2024