Red Hat / Build of Quarkus
21 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-6394 | Quarkus: graphql operations over websockets bypass | CRITICAL | 9.1 | Dec 9, 2023 |
| CVE-2023-6393 | Quarkus: potential invalid reuse of context when @cacheresult on a uni is used | MEDIUM | 5.3 | Dec 6, 2023 |
| CVE-2023-44487 KEV | HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) | MEDIUM | 6.9 | Oct 10, 2023 |
| CVE-2023-4853 | Quarkus: http security policy bypass | HIGH | 8.1 | Sep 20, 2023 |
| CVE-2023-1108 | Undertow: infinite loop in sslconduit during close | HIGH | 7.5 | Sep 14, 2023 |
| CVE-2023-2974 | Quarkus-core: tls protocol configured with quarkus.http.ssl.protocols is not enforced, client can enforce weaker supported tls protocol | HIGH | 8.1 | Jul 4, 2023 |
| CVE-2023-1664 | keycloak: Untrusted Certificate Validation | MEDIUM | 6.5 | May 26, 2023 |
| CVE-2023-0044 | quarkus-vertx-http: a cross-site attack may be initiated which might lead to the Information Disclosure | MEDIUM | 6.1 | Feb 23, 2023 |
| CVE-2022-4492 | undertow: Server identity in https connection is not checked by the undertow client | CRITICAL | 9.8 | Feb 23, 2023 |
| CVE-2022-4116 | quarkus_dev_ui: Dev UI Config Editor is vulnerable to drive-by localhost attacks leading to RCE | CRITICAL | 9.8 | Nov 22, 2022 |
| CVE-2022-1259 | undertow: potential security issue in flow control over HTTP/2 may lead to DOS(incomplete fix for CVE-2021-3629) | HIGH | 7.5 | Aug 31, 2022 |
| CVE-2021-3669 | kernel: reading /proc/sysvipc/shm does not scale with large shared memory segment counts | MEDIUM | 5.5 | Aug 26, 2022 |
| CVE-2021-3914 | smallrye-health-ui: persistent cross-site scripting in endpoint | MEDIUM | 6.5 | Aug 25, 2022 |
| CVE-2021-4178 | kubernetes-client: Insecure deserialization in unmarshalYaml method | MEDIUM | 6.7 | Aug 24, 2022 |
| CVE-2022-1011 | kernel: FUSE allows UAF reads of write() buffers, allowing theft of (partial) /etc/shadow hashes | HIGH | 7.8 | Mar 18, 2022 |
| CVE-2021-3744 | kernel: crypto: ccp - fix resource leaks in ccp_run_aes_gcm_cmd() | MEDIUM | 5.5 | Mar 4, 2022 |
| CVE-2021-3609 | kernel: race condition in net/can/bcm.c leads to local privilege escalation | HIGH | 7.0 | Mar 3, 2022 |
| CVE-2021-3642 | wildfly-elytron: possible timing attack in ScramServer | MEDIUM | 5.3 | Aug 5, 2021 |
| CVE-2021-3536 | wildfly: XSS via admin console when creating roles in domain mode | MEDIUM | 4.8 | May 20, 2021 |
| CVE-2021-20218 | fabric8-kubernetes-client: vulnerable to a path traversal leading to integrity and availability compromise | HIGH | 7.4 | Mar 16, 2021 |
| CVE-2019-14900 | hibernate: SQL injection issue in Hibernate ORM | MEDIUM | 6.5 | Jul 6, 2020 |
Showing 1 to 21 of 21 CVEs