Impact
The vulnerability originates in the Quarkus Qute template engine where the {#eval} section helper neglects to propagate the parent template’s content type information. This oversight disables the usual escaping routines and lets untrusted data be rendered as raw, unescaped output. The result is the potential for Cross‑Site Scripting and JSON injection, allowing a malicious actor to run arbitrary code in a user’s browser or alter injected data structures.
Affected Systems
Affected products are predominantly Red Hat‑maintained components that rely on Quarkus. The vulnerable Quarkus Qute engine is bundled in Red Hat Fuse 7, Red Hat Build of Keycloak, the Red Hat build of Apache Camel 4 for Quarkus 3, the Red Hat build of Apicurio Registry 3, and the Red Hat build of Quarkus 3. These include the Red Hat Exploit Intelligence component as well.
Risk and Exploitability
The CVSS score of 6.1 classifies the issue as moderate, but the lack of an EPSS score and absence from the KEV database suggest that public exploitation has not yet been demonstrated. The likely attack vector is a web application that renders dynamic templates containing untrusted input; the attacker can supply malicious payloads that will bypass escaping and execute in clients visiting the rendered page.
OpenCVE Enrichment