MEDIUM🇵🇱 Wersja polska

CVE-2023-2974

CVSS 6.5v3.1pub. 2023-07-04upd. 2024-11-21

A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force the selection of the weaker supported TLS protocol.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
  • Red Hat Build Of Quarkus

    APP
    Redhat
    < 2.13.8
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-4116CRITICAL9.8PL ✓same product

RCE w Quarkus Dev UI Config Editor poprzez drive-by localhost attack

CVE-2023-6394HIGH7.4same product

A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based perm...

CVE-2023-4853HIGH8.1same product

A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations cor...

CVE-2023-1108HIGH7.5same product

A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected han...

CVE-2022-4492HIGH7.5same product

The undertow client is not checking the server identity presented by the server certificate in https connectio...