A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-2099 A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.
Github GHSA Github GHSA GHSA-phg3-gv66-q38x Quarkus REST Endpoint Request Parameter Leakage Due to Shared Instance
Fixes

Solution

No solution given by the vendor.


Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00031}

epss

{'score': 0.00034}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00037}

epss

{'score': 0.00031}


Mon, 03 Mar 2025 13:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:camel_quarkus:3 cpe:/a:redhat:camel_quarkus:3.15
References

Thu, 27 Feb 2025 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:quarkus:3.8::el8
References

Thu, 27 Feb 2025 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:quarkus:3 cpe:/a:redhat:quarkus:3.15::el8
References

Thu, 13 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Feb 2025 13:30:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.
Title io.quarkus:quarkus-rest: Quarkus REST Endpoint Request Parameter Leakage Due to Shared Instance Io.quarkus:quarkus-rest: quarkus rest endpoint request parameter leakage due to shared instance
First Time appeared Redhat
Redhat camel Quarkus
Redhat quarkus
CPEs cpe:/a:redhat:camel_quarkus:3
cpe:/a:redhat:quarkus:3
Vendors & Products Redhat
Redhat camel Quarkus
Redhat quarkus
References

Wed, 12 Feb 2025 13:45:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title io.quarkus:quarkus-rest: Quarkus REST Endpoint Request Parameter Leakage Due to Shared Instance
Weaknesses CWE-488
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}

threat_severity

Important


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-08-27T13:34:39.050Z

Reserved: 2025-02-12T09:43:11.716Z

Link: CVE-2025-1247

cve-icon Vulnrichment

Updated: 2025-02-13T14:11:35.346Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-13T14:16:18.400

Modified: 2025-03-03T14:15:34.120

Link: CVE-2025-1247

cve-icon Redhat

Severity : Important

Publid Date: 2025-02-12T00:00:00Z

Links: CVE-2025-1247 - Bugzilla

cve-icon OpenCVE Enrichment

No data.