Impact
A flaw has been discovered in the IBM Enterprise Build of Quarkus. By manipulating URL query parameters, a remote attacker can cause the application to incorrectly map those parameters to untrusted input, enabling the attacker to bypass authorization checks and gain unauthorized access to protected resources. The weakness aligns with CWE-551 and CWE-639, representing an Authorization Bypass through User-Controlled Key and an improper handling of untrusted input.
Affected Systems
The vulnerability affects the IBM Enterprise Build of Quarkus. Versions 3.27.1 through 3.27.5 and 3.33.1 through 3.33.3 are affected. Any deployment of these versions may be vulnerable until a fix is released.
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity. The absence of an EPSS score and KEV listing makes the exploitation probability uncertain. However, the flaw permits remote authorization bypass, which is significant because it allows an attacker to access any protected resource without credentials. Attackers can trigger the vulnerability by sending a crafted HTTP request with a specially formed query string. Until a patch is applied, the project remains at risk for unauthorized access.
OpenCVE Enrichment