CVE-2023-6394 – io.quarkus:quarkus-smallrye-graphql-client
Package
Manager: maven
Name: io.quarkus:quarkus-smallrye-graphql-client
Vulnerable Version: >=2.14.0 <3.5.3 || >=0 <2.13.9.final
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00285 pctl0.515
Details
Authorization bypass in Quarkus A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.
Metadata
Created: 2023-12-09T03:30:15Z
Modified: 2024-08-02T15:31:16Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-mvc8-6ffp-jrx5/GHSA-mvc8-6ffp-jrx5.json
CWE IDs: ["CWE-696", "CWE-862"]
Alternative ID: GHSA-mvc8-6ffp-jrx5
Finding: F039
Auto approve: 1