Tls protocol configured with quarkus.http.ssl.protocols is not enforced, client can enforce weaker supported tls protocol
CVE-2023-2974
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 4 July 2023
What is CVE-2023-2974?
A configuration flaw exists in the quarkus-core TLS protocol implementation that permits clients to select a weaker supported TLS version when the server should enforce strict protocol levels. This misconfiguration can expose systems to potential interception and downgrade attacks, affecting the overall integrity of data transmitted over secure channels. Proper enforcement of the TLS protocol settings is required to mitigate the risk associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Red Hat build of Quarkus 2.13.8.Final 2.13.8.Final-redhat-00004
Red Hat build of Quarkus 2.13.8.Final 2.13.8.Final-redhat-00004
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved