logo

CVE-2023-6394 io.quarkus:quarkus-smallrye-graphql-client

Package

Manager: maven
Name: io.quarkus:quarkus-smallrye-graphql-client
Vulnerable Version: >=2.14.0 <3.5.3 || >=0 <2.13.9.final

Severity

Level: High

CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00285 pctl0.515

Details

Authorization bypass in Quarkus A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.

Metadata

Created: 2023-12-09T03:30:15Z
Modified: 2024-08-02T15:31:16Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-mvc8-6ffp-jrx5/GHSA-mvc8-6ffp-jrx5.json
CWE IDs: ["CWE-696", "CWE-862"]
Alternative ID: GHSA-mvc8-6ffp-jrx5
Finding: F039
Auto approve: 1