PT-2023-3549 · Unknown · Quarkus-Core

Alexander Schwartz

+1

·

Published

2023-05-30

·

Updated

2023-07-11

·

CVE-2023-2974

CVSS v2.0

7.7

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions quarkus-core (affected versions not specified)
Description A vulnerability was found in the implementation of the TLS protocol in the Quarkus Java framework. This issue is related to the insufficient reliability of encryption when using the quarkus.http.ssl.protocols configuration. The vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, allowing a client to force the selection of a weaker supported TLS protocol. This could potentially allow a remote attacker to gain unauthorized access to protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

BDU:2023-03765
CVE-2023-2974
GHSA-3FHX-3VVG-2J84

Affected Products

Quarkus-Core