PT-2022-6100 · Quarkus · Quarkus
Joseph Beeton
·
Published
2022-11-22
·
Updated
2025-04-29
·
CVE-2022-4116
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
quarkus (affected versions not specified)
Description
The issue is related to the Dev UI Config Editor component of the quarkus Java framework, which is vulnerable to remote code execution due to incorrect code generation management. This can allow a remote attacker to execute arbitrary code. The vulnerability is also described as being susceptible to drive-by localhost attacks.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Code Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Quarkus