If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented with the Quarkus CSRF Prevention feature.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0689 | If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented with the Quarkus CSRF Prevention feature. |
Github GHSA |
GHSA-c57v-hc7m-8px2 | Cross-site Scripting in Quarkus |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 12 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-03-12T14:32:14.395Z
Reserved: 2023-01-04T00:00:00.000Z
Link: CVE-2023-0044
Updated: 2024-08-02T04:54:32.575Z
Status : Modified
Published: 2023-02-23T20:15:12.823
Modified: 2024-11-21T07:36:27.050
Link: CVE-2023-0044
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA