PT-2023-8750 · Quarkus · Quarkus
Sandipan Roy
·
Published
2023-01-04
·
Updated
2023-03-03
·
CVE-2023-0044
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Quarkus (affected versions not specified)
Description
The issue is related to the Quarkus Form Authentication session cookie Path attribute being set to
/, which may lead to a cross-site attack and potentially result in Information Disclosure. This can be prevented by using the Quarkus CSRF Prevention feature. The vulnerability is also associated with a lack of protection for the web page structure, which could allow a remote attacker to conduct a cross-site scripting (XSS) attack.Recommendations
As a temporary workaround, consider using the Quarkus CSRF Prevention feature to prevent cross-site attacks.
Restrict access to the Quarkus Form Authentication session cookie to minimize the risk of exploitation.
Avoid setting the Path attribute of the Quarkus Form Authentication session cookie to
/ until a more secure configuration is implemented.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quarkus