Quarkus: graphql operations over websockets bypass
CVE-2023-6394
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 9 December 2023
What is CVE-2023-6394?
A flaw exists in Quarkus that allows unauthorized access via websocket requests. When specific role-based permissions are not defined for GraphQL operations, Quarkus processes incoming requests without proper authentication, compromising the security of endpoints intended to be protected. This flaw potentially enables attackers to exploit existing permissions to access sensitive information and functionalities that should otherwise remain restricted.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Red Hat build of Quarkus 2.13.9.Final 2.13.9.Final-redhat-00002
Red Hat build of Quarkus 3.2.9.Final 3.2.9.Final-redhat-00002
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved