SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-4853

This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.

HIGH 8.1EPSS 1.44%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.44%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.

CVSS 3.1
8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.44% probability · 72th percentile
CISA KEV
Not listed
Weakness
CWE-148, CWE-863
Affected
quarkus/quarkus · redhat/build of optaplanner · redhat/build of quarkus · redhat/decision manager · redhat/integration camel k · redhat/integration camel quarkus · redhat/integration service registry · redhat/jboss middleware · redhat/jboss middleware text-only advisories · redhat/openshift serverless · redhat/process automation manager · redhat/openshift container platform
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.