A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force the selection of the weaker supported TLS protocol.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1937 | A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force the selection of the weaker supported TLS protocol. |
Github GHSA |
GHSA-3fhx-3vvg-2j84 | quarkus-core vulnerable to client driven TLS cipher downgrading |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-02T06:41:03.976Z
Reserved: 2023-05-30T10:06:53.993Z
Link: CVE-2023-2974
No data.
Status : Modified
Published: 2023-07-04T14:15:09.473
Modified: 2024-11-21T07:59:40.557
Link: CVE-2023-2974
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA