Quarkus: graphql operations over websockets bypass
CVE-2023-6394
7.4HIGH
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 9 December 2023
What is CVE-2023-6394?
A flaw exists in Quarkus that allows unauthorized access via websocket requests. When specific role-based permissions are not defined for GraphQL operations, Quarkus processes incoming requests without proper authentication, compromising the security of endpoints intended to be protected. This flaw potentially enables attackers to exploit existing permissions to access sensitive information and functionalities that should otherwise remain restricted.
Affected Version(s)
Red Hat build of Quarkus 2.13.9.Final 2.13.9.Final-redhat-00002
Red Hat build of Quarkus 3.2.9.Final 3.2.9.Final-redhat-00002