PT-2023-3549 · Unknown · Quarkus-Core
Alexander Schwartz
+1
·
Published
2023-05-30
·
Updated
2023-07-11
·
CVE-2023-2974
CVSS v2.0
7.7
High
| Vector | AV:N/AC:L/Au:M/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
quarkus-core (affected versions not specified)
Description
A vulnerability was found in the implementation of the TLS protocol in the Quarkus Java framework. This issue is related to the insufficient reliability of encryption when using the quarkus.http.ssl.protocols configuration. The vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, allowing a client to force the selection of a weaker supported TLS protocol. This could potentially allow a remote attacker to gain unauthorized access to protected information.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Quarkus-Core