Impact
A flaw has been discovered in quarkus-spring-web. By manipulating the URL query string, a remote attacker can cause the application to interpret the query string as a request header. This misinterpretation allows the attacker to bypass authorization checks and gain unauthorized access to protected resources. The weakness aligns with CWE-551, an Authorization Bypass through User-Controlled Key.
Affected Systems
The vulnerability affects the quarkus-spring-web component of the Quarkus framework. Specific affected versions are not listed in the available data, so any deployment that includes quarkus-spring-web may be susceptible until a fix is released.
Risk and Exploitability
The absence of an EPSS score and KEV listing makes the exploitation probability uncertain. However, the flaw permits remote authorization bypass, which is significant because it allows an attacker to access any protected resource without credentials. Attackers can trigger the vulnerability by sending a crafted HTTP request with a specially formed query string. Until a patch is applied, the project remains at risk for unauthorized access.
OpenCVE Enrichment