quarkus_dev_ui: Dev UI Config Editor is vulnerable to drive-by localhost attacks leading to RCE
Published Nov 22, 2022
9.8
CRITICALCVSS 3.1
EPSS 32.52%
Description
A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution.
Affected products
- Vendor n/a Product Quarkus Defaultn/a
- Version quarkus-2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Quarkus | n/a |
|
No data.
Red Hat build of Quarkus 2.13.5
n/a
Fixed · RHSA-2022:9023
Red Hat build of Quarkus Platform 2.7.6.SP3
quarkus_dev_ui
Fixed · RHSA-2022:8957
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat build of Quarkus 2.13.5 | n/a | Fixed | RHSA-2022:9023 |
| Red Hat build of Quarkus Platform 2.7.6.SP3 | quarkus_dev_ui | Fixed | RHSA-2022:8957 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Apr 29, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (29 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 32.52% (0.32516) | 98.29th | v5 (v2026.06.15) |
| Jun 15, 2026 | 32.52% (0.32516) | 98.11th | v5 (v2026.06.15) |
| Feb 4, 2026 | 2.90% (0.02900) | 86.01th | v4 (v2025.03.14) |
| Jan 5, 2026 | 11.88% (0.11875) | 93.50th | v4 (v2025.03.14) |
| Dec 16, 2025 | 16.09% (0.16094) | 94.55th | v4 (v2025.03.14) |
| Dec 15, 2025 | 21.93% (0.21934) | 95.56th | v4 (v2025.03.14) |
| Nov 29, 2025 | 18.90% (0.18898) | 95.06th | v4 (v2025.03.14) |
| Nov 21, 2025 | 23.21% (0.23212) | 95.72th | v4 (v2025.03.14) |
| Nov 18, 2025 | 2.13% (0.02132) | 82.78th | v4 (v2025.03.14) |
| Sep 18, 2025 | 23.21% (0.23212) | 95.74th | v4 (v2025.03.14) |
| Aug 17, 2025 | 22.15% (0.22149) | 95.56th | v4 (v2025.03.14) |
| Mar 30, 2025 | 20.69% (0.20685) | 95.11th | v4 (v2025.03.14) |
| Mar 29, 2025 | 39.85% (0.39846) | 95.96th | v4 (v2025.03.14) |
| Mar 17, 2025 | 20.69% (0.20685) | 95.12th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.83% (0.00826) | 82.64th | v3 (v2023.03.01) |
| Jun 29, 2024 | 0.73% (0.00730) | 80.85th | v3 (v2023.03.01) |
| Jun 14, 2024 | 0.70% (0.00701) | 80.36th | v3 (v2023.03.01) |
| May 4, 2024 | 0.66% (0.00660) | 79.47th | v3 (v2023.03.01) |
| Feb 27, 2024 | 0.67% (0.00671) | 79.22th | v3 (v2023.03.01) |
| Dec 25, 2023 | 0.47% (0.00473) | 73.03th | v3 (v2023.03.01) |
| Nov 29, 2023 | 0.57% (0.00566) | 75.25th | v3 (v2023.03.01) |
| Aug 13, 2023 | 0.29% (0.00286) | 64.70th | v3 (v2023.03.01) |
| Aug 4, 2023 | 0.41% (0.00406) | 70.34th | v3 (v2023.03.01) |
| May 8, 2023 | 0.29% (0.00286) | 63.98th | v3 (v2023.03.01) |
| Mar 27, 2023 | 0.40% (0.00395) | 69.29th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.41% (0.00415) | 70.03th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.16% (0.01156) | 61.37th | v2 (v2022.01.01) |
| Nov 26, 2022 | 1.16% (0.01156) | 60.51th | v2 (v2022.01.01) |
| Nov 23, 2022 | 2.72% (0.02722) | 82.37th | v2 (v2022.01.01) |
References (7)
- https://access.redhat.com/security/cve/CVE-2022-4116 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2144748 Issue Tracking
- https://github.com/advisories/GHSA-g56w-cwg4-hxx9 Advisory
- https://github.com/quarkusio/quarkus/discussions/29527
- https://github.com/quarkusio/quarkus/discussions/29527#discussioncomment-4387809
- https://nvd.nist.gov/vuln/detail/CVE-2022-4116
- https://www.cve.org/CVERecord?id=CVE-2022-4116
Change history (0)
No recorded changes yet.