Quarkus: http security policy bypass
Published Sep 20, 2023
8.1
HIGHCVSS 3.1
EPSS 1.45%
Description
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Process Automation 7 | affected |
| |||
| Red Hat | Red Hat build of Quarkus | affected |
|
Configuration 1
Configuration 2
- 8.0
- ≥ 2.13.0 · < 2.13.8
- 7.0
- < 1.10.2
- n/a
- n/a
- 1
- 1.0
- n/a
- 1.0
- 7.0
Configuration 3
- 4.10
- 4.11
- 4.12
Running on/with
- 8.0
No data.
Openshift Serverless 1 on RHEL 8
openshift-serverless-clients-0:1.9.2-3.el8
Fixed · RHSA-2023:5479
RHEL-8 based Middleware Containers
rhpam-7-tech-preview/rhpam-kogito-runtime-native-rhel8:7.13.4-3
Fixed · RHSA-2023:6107
RHEL-8 based Middleware Containers
rhpam-7/rhpam-kogito-builder-rhel8:7.13.4-3
Fixed · RHSA-2023:6107
RHEL-8 based Middleware Containers
rhpam-7/rhpam-kogito-rhel8-operator-bundle:7.13.4-2
Fixed · RHSA-2023:6107
RHEL-8 based Middleware Containers
rhpam-7/rhpam-kogito-rhel8-operator:7.13.4-2
Fixed · RHSA-2023:6107
RHEL-8 based Middleware Containers
rhpam-7/rhpam-kogito-runtime-jvm-rhel8:7.13.4-3
Fixed · RHSA-2023:6107
RHINT Camel-K-1.10.2
quarkus-vertx-http
Fixed · RHSA-2023:5337
RHINT Service Registry 2.5.4 GA
quarkus-vertx-http
Fixed · RHSA-2023:7653
RHPAM 7.13.4 async
n/a
Fixed · RHSA-2023:6112
Red Hat Camel Extensions for Quarkus 2.13.3-1
quarkus-vertx-http
Fixed · RHSA-2023:5310
Red Hat OpenShift Serverless 1.30
openshift-serverless-1-tech-preview/logic-data-index-ephemeral-rhel8:1.30.0-5
Fixed · RHSA-2023:5480
Red Hat OpenShift Serverless 1.30
openshift-serverless-1-tech-preview/logic-swf-builder-rhel8:1.30.0-6
Fixed · RHSA-2023:5480
Red Hat OpenShift Serverless 1.30
openshift-serverless-1-tech-preview/logic-swf-devmode-rhel8:1.30.0-6
Fixed · RHSA-2023:5480
Red Hat OpenShift Serverless 1.30
openshift-serverless-1/client-kn-rhel8:1.9.2-3
Fixed · RHSA-2023:5480
Red Hat OpenShift Serverless 1.30
openshift-serverless-1/ingress-rhel8-operator:1.30.1-1
Fixed · RHSA-2023:5480
Red Hat OpenShift Serverless 1.30
openshift-serverless-1/kn-cli-artifacts-rhel8:1.9.2-3
Fixed · RHSA-2023:5480
Red Hat OpenShift Serverless 1.30
openshift-serverless-1/knative-rhel8-operator:1.30.1-1
Fixed · RHSA-2023:5480
Red Hat OpenShift Serverless 1.30
openshift-serverless-1/serverless-operator-bundle:1.30.1-1
Fixed · RHSA-2023:5480
Red Hat OpenShift Serverless 1.30
openshift-serverless-1/serverless-rhel8-operator:1.30.1-1
Fixed · RHSA-2023:5480
Red Hat OpenShift Serverless 1.30
openshift-serverless-1/svls-must-gather-rhel8:1.30.1-1
Fixed · RHSA-2023:5480
Red Hat build of OptaPlanner 8
quarkus-vertx-http
Fixed · RHSA-2023:5446
Red Hat build of Quarkus 2.13.8.SP2
io.quarkus/quarkus-keycloak-authorization:2.13.8.Final-redhat-00005
Fixed · RHSA-2023:5170
Red Hat build of Quarkus 2.13.8.SP2
io.quarkus/quarkus-undertow:2.13.8.Final-redhat-00005
Fixed · RHSA-2023:5170
Red Hat build of Quarkus 2.13.8.SP2
io.quarkus/quarkus-vertx-http:2.13.8.Final-redhat-00005
Fixed · RHSA-2023:5170
Red Hat Process Automation 7
quarkus-vertx-http
Will not fix
Red Hat build of Quarkus
quarkus-keycloak-authorization
Affected
Red Hat build of Quarkus
quarkus-undertow
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Openshift Serverless 1 on RHEL 8 | openshift-serverless-clients-0:1.9.2-3.el8 | Fixed | RHSA-2023:5479 |
| RHEL-8 based Middleware Containers | rhpam-7-tech-preview/rhpam-kogito-runtime-native-rhel8:7.13.4-3 | Fixed | RHSA-2023:6107 |
| RHEL-8 based Middleware Containers | rhpam-7/rhpam-kogito-builder-rhel8:7.13.4-3 | Fixed | RHSA-2023:6107 |
| RHEL-8 based Middleware Containers | rhpam-7/rhpam-kogito-rhel8-operator-bundle:7.13.4-2 | Fixed | RHSA-2023:6107 |
| RHEL-8 based Middleware Containers | rhpam-7/rhpam-kogito-rhel8-operator:7.13.4-2 | Fixed | RHSA-2023:6107 |
| RHEL-8 based Middleware Containers | rhpam-7/rhpam-kogito-runtime-jvm-rhel8:7.13.4-3 | Fixed | RHSA-2023:6107 |
| RHINT Camel-K-1.10.2 | quarkus-vertx-http | Fixed | RHSA-2023:5337 |
| RHINT Service Registry 2.5.4 GA | quarkus-vertx-http | Fixed | RHSA-2023:7653 |
| RHPAM 7.13.4 async | n/a | Fixed | RHSA-2023:6112 |
| Red Hat Camel Extensions for Quarkus 2.13.3-1 | quarkus-vertx-http | Fixed | RHSA-2023:5310 |
| Red Hat OpenShift Serverless 1.30 | openshift-serverless-1-tech-preview/logic-data-index-ephemeral-rhel8:1.30.0-5 | Fixed | RHSA-2023:5480 |
| Red Hat OpenShift Serverless 1.30 | openshift-serverless-1-tech-preview/logic-swf-builder-rhel8:1.30.0-6 | Fixed | RHSA-2023:5480 |
| Red Hat OpenShift Serverless 1.30 | openshift-serverless-1-tech-preview/logic-swf-devmode-rhel8:1.30.0-6 | Fixed | RHSA-2023:5480 |
| Red Hat OpenShift Serverless 1.30 | openshift-serverless-1/client-kn-rhel8:1.9.2-3 | Fixed | RHSA-2023:5480 |
| Red Hat OpenShift Serverless 1.30 | openshift-serverless-1/ingress-rhel8-operator:1.30.1-1 | Fixed | RHSA-2023:5480 |
| Red Hat OpenShift Serverless 1.30 | openshift-serverless-1/kn-cli-artifacts-rhel8:1.9.2-3 | Fixed | RHSA-2023:5480 |
| Red Hat OpenShift Serverless 1.30 | openshift-serverless-1/knative-rhel8-operator:1.30.1-1 | Fixed | RHSA-2023:5480 |
| Red Hat OpenShift Serverless 1.30 | openshift-serverless-1/serverless-operator-bundle:1.30.1-1 | Fixed | RHSA-2023:5480 |
| Red Hat OpenShift Serverless 1.30 | openshift-serverless-1/serverless-rhel8-operator:1.30.1-1 | Fixed | RHSA-2023:5480 |
| Red Hat OpenShift Serverless 1.30 | openshift-serverless-1/svls-must-gather-rhel8:1.30.1-1 | Fixed | RHSA-2023:5480 |
| Red Hat build of OptaPlanner 8 | quarkus-vertx-http | Fixed | RHSA-2023:5446 |
| Red Hat build of Quarkus 2.13.8.SP2 | io.quarkus/quarkus-keycloak-authorization:2.13.8.Final-redhat-00005 | Fixed | RHSA-2023:5170 |
| Red Hat build of Quarkus 2.13.8.SP2 | io.quarkus/quarkus-undertow:2.13.8.Final-redhat-00005 | Fixed | RHSA-2023:5170 |
| Red Hat build of Quarkus 2.13.8.SP2 | io.quarkus/quarkus-vertx-http:2.13.8.Final-redhat-00005 | Fixed | RHSA-2023:5170 |
| Red Hat Process Automation 7 | quarkus-vertx-http | Will not fix | n/a |
| Red Hat build of Quarkus | quarkus-keycloak-authorization | Affected | n/a |
| Red Hat build of Quarkus | quarkus-undertow | Affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Use a ‘deny’ wildcard for base paths, then authenticate specifics within that:
Examples: ``` deny: /* authenticated: /services/* ``` or ``` deny: /services/* roles-allowed: /services/rbac/* ```
NOTE: Products are only vulnerable if they use (or allow use of) path-based HTTP policy configuration. Products may also be affected–shipping the component in question–without being vulnerable (“affected at reduced impact”).
See https://access.redhat.com/security/vulnerabilities/RHSB-2023-002 for more detailed mitigations.
Red Hat mitigation
Use a ‘deny’ wildcard for base paths, then authenticate specifics within that: Examples: ``` deny: /* authenticated: /services/* ``` or ``` deny: /services/* roles-allowed: /services/rbac/* ``` NOTE: Products are only vulnerable if they use (or allow use of) path-based HTTP policy configuration. Products may also be affected–shipping the component in question–without being vulnerable (“affected at reduced impact”). See https://access.redhat.com/security/vulnerabilities/RHSB-2023-002 for more detailed mitigations.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.45% (0.01449) | 72.41th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.21% (0.01215) | 64.47th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.35% (0.00348) | 56.69th | v4 (v2025.03.14) |
| Nov 18, 2025 | 4.53% (0.04531) | 88.06th | v4 (v2025.03.14) |
| Apr 15, 2025 | 0.58% (0.00577) | 67.48th | v4 (v2025.03.14) |
| Mar 30, 2025 | 4.53% (0.04531) | 88.12th | v4 (v2025.03.14) |
| Mar 29, 2025 | 8.82% (0.08822) | 87.35th | v4 (v2025.03.14) |
| Mar 17, 2025 | 4.53% (0.04531) | 88.43th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.37% (0.00374) | 73.59th | v3 (v2023.03.01) |
| Dec 6, 2023 | 0.21% (0.00206) | 58.28th | v3 (v2023.03.01) |
| Oct 26, 2023 | 0.20% (0.00199) | 57.50th | v3 (v2023.03.01) |
| Oct 6, 2023 | 0.15% (0.00151) | 50.92th | v3 (v2023.03.01) |
| Oct 5, 2023 | 0.14% (0.00143) | 49.68th | v3 (v2023.03.01) |
| Sep 28, 2023 | 0.09% (0.00093) | 39.04th | v3 (v2023.03.01) |
| Sep 26, 2023 | 0.10% (0.00101) | 40.82th | v3 (v2023.03.01) |
| Sep 22, 2023 | 0.04% (0.00045) | 12.75th | v3 (v2023.03.01) |
References (18)
- https://access.redhat.com/articles/11258
- https://access.redhat.com/errata/RHSA-2023:5170 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2023:5310 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2023:5337 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2023:5446 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2023:5479 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2023:5480 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2023:6107 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2023:6112 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2023:7653 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2023-4853 vdb-entryx_refsource_REDHATMitigationVendor Advisory
- https://access.redhat.com/security/vulnerabilities/RHSB-2023-002 technical-descriptionx_refsource_REDHATExploitMitigationTechnical DescriptionVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2238034 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://github.com/advisories/GHSA-4f4r-wgv2-jjvg Advisory
- https://github.com/quarkusio/quarkus/discussions/35940
- https://github.com/quarkusio/quarkus/issues/35785
- https://nvd.nist.gov/vuln/detail/CVE-2023-4853
- https://www.cve.org/CVERecord?id=CVE-2023-4853
Change history (0)
No recorded changes yet.