[MAVEN:GHSA-8J3X-W35R-RW4R] Quarkus Improper Handling of Insufficient Permissions or Privileges and Improper Handling of Exceptional Conditions vulnerability

Severity High
Affected Packages 2
Fixed Packages 2
CVEs 1

A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource may consume is being processed (deserialized) prior to the security constraints being evaluated and applied. This does not happen with configuration based security.

ID
MAVEN:GHSA-8J3X-W35R-RW4R
Severity
high
URL
https://github.com/advisories/GHSA-8j3x-w35r-rw4r
Published
2024-01-25T21:32:14
(7 months ago)
Modified
2024-01-31T22:39:01
(7 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/io.quarkus.resteasy.reactive/resteasy-reactive io.quarkus.resteasy.reactive resteasy-reactive >= 3.0.0.Final < 3.2.9.Final
Fixed pkg:maven/io.quarkus.resteasy.reactive/resteasy-reactive io.quarkus.resteasy.reactive resteasy-reactive = 3.2.9.Final
Affected pkg:maven/io.quarkus.resteasy.reactive/resteasy-reactive io.quarkus.resteasy.reactive resteasy-reactive < 2.13.9.Final
Fixed pkg:maven/io.quarkus.resteasy.reactive/resteasy-reactive io.quarkus.resteasy.reactive resteasy-reactive = 2.13.9.Final
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...