CVE-2022-2466

CVSS v3.1 9.8 (Critical)
98% Progress
EPSS 0.19 % (57th)
0.19% Progress
Affected Products 1
Advisories 1

It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavior.

Weaknesses
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2022-08-31 16:15:10
(2 years ago)
Updated Date
2022-09-06 22:09:21
(2 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Quarkus from 2.10.0 version and prior 2.10.4 version cpe:2.3:a:quarkus:quarkus >= 2.10.0 < 2.10.4
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...