PT-2023-8750 · Quarkus · Quarkus

Sandipan Roy

·

Published

2023-01-04

·

Updated

2023-03-03

·

CVE-2023-0044

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Quarkus (affected versions not specified)
Description The issue is related to the Quarkus Form Authentication session cookie Path attribute being set to /, which may lead to a cross-site attack and potentially result in Information Disclosure. This can be prevented by using the Quarkus CSRF Prevention feature. The vulnerability is also associated with a lack of protection for the web page structure, which could allow a remote attacker to conduct a cross-site scripting (XSS) attack.
Recommendations As a temporary workaround, consider using the Quarkus CSRF Prevention feature to prevent cross-site attacks. Restrict access to the Quarkus Form Authentication session cookie to minimize the risk of exploitation. Avoid setting the Path attribute of the Quarkus Form Authentication session cookie to / until a more secure configuration is implemented.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-01801
CVE-2023-0044
GHSA-C57V-HC7M-8PX2

Affected Products

Quarkus