Aller au contenu

Fiche vulnérabilité

CVE-2023-6267 : faille critique quarkus quarkus (CVSS 9.8)

Description

A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource may consume is being processed (deserialized) prior to the security constraints being evaluated and applied. This does not happen with configuration based security.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
25 janv. 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • quarkus quarkus

Références

Rechercher une autre vulnérabilité dans la base CVE