Back

MEDIUM

quarkus-vertx-http: a cross-site attack may be initiated which might lead to the Information Disclosure

Published Feb 23, 2023

Description

If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented with the Quarkus CSRF Prevention feature.

Affected products

Remediation

Red Hat mitigation

This attack can be prevented with the Quarkus CSRF Prevention feature.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 23, 2023
Updated Mar 12, 2025
Reserved Jan 4, 2023
CISA Vulnrichment
Updated Mar 12, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jan 4, 2023
GHSA-C57V-HC7M-8PX2