PT-2024-5140 · Quarkus · Quarkus

Michal Vavřík

+1

·

Published

2024-02-20

·

Updated

2024-04-25

·

CVE-2024-1726

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions: Quarkus (affected versions not specified)
Description: The issue is related to a flaw in the RESTEasy Reactive implementation, where security checks for some JAX-RS endpoints are performed after serialization, leading to increased resource consumption. An attacker with knowledge of specific request paths can potentially identify vulnerable endpoints and trigger excessive resource usage, resulting in a denial of service. The estimated number of potentially affected devices and details about real-world incidents are not provided.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Preservation of Permissions

Weakness Enumeration

Related Identifiers

BDU:2024-05687
CVE-2024-1726
GHSA-MV64-86G8-CQQ7

Affected Products

Quarkus