Back

HIGH

quarkus-vertx-http: Security misconfiguration of CORS : OWASP A05_2021 level in Quarkus

Published Dec 6, 2022

Description

Quarkus CORS filter allows simple GET and POST requests with invalid Origin to proceed. Simple GET or POST requests made with XMLHttpRequest are the ones which have no event listeners registered on the object returned by the XMLHttpRequest upload property and have no ReadableStream object used in the request.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 6, 2022
Updated Apr 14, 2025
Reserved Nov 28, 2022
CISA Vulnrichment
Updated Apr 14, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 28, 2022
GHSA-9895-G6X5-XWCP