Back

HIGH

Quarkus: http security policy bypass

Published Sep 20, 2023

Description

A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.

Affected products

Remediation

Vendor solution

Use a ‘deny’ wildcard for base paths, then authenticate specifics within that:

Examples: ``` deny: /* authenticated: /services/* ``` or ``` deny: /services/* roles-allowed: /services/rbac/* ```

NOTE: Products are only vulnerable if they use (or allow use of) path-based HTTP policy configuration. Products may also be affected–shipping the component in question–without being vulnerable (“affected at reduced impact”).

See https://access.redhat.com/security/vulnerabilities/RHSB-2023-002 for more detailed mitigations.

Red Hat mitigation

Use a ‘deny’ wildcard for base paths, then authenticate specifics within that: Examples: ``` deny: /* authenticated: /services/* ``` or ``` deny: /services/* roles-allowed: /services/rbac/* ``` NOTE: Products are only vulnerable if they use (or allow use of) path-based HTTP policy configuration. Products may also be affected–shipping the component in question–without being vulnerable (“affected at reduced impact”). See https://access.redhat.com/security/vulnerabilities/RHSB-2023-002 for more detailed mitigations.

Metrics

References (18)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 20, 2023
Updated Aug 4, 2026
Reserved Sep 8, 2023
NVD
Status Modified
Modified Aug 4, 2026
Red Hat
Severity Important
Public date Sep 8, 2023
GHSA-4F4R-WGV2-JJVG