CVE-2023-6267
Java vulnerability analysis and mitigation

Overview

CVE-2023-6267 is a security vulnerability discovered in Quarkus, affecting the JSON payload processing in REST resources. The vulnerability was disclosed on January 25, 2024, and affects Quarkus versions up to 2.13.9 and versions from 3.0.0 up to 3.2.9. The flaw occurs when annotation-based security is used to secure a REST resource, where the JSON body is processed (deserialized) before security constraints are evaluated and applied (NVD).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 9.8 (CRITICAL) by NIST and 8.6 (HIGH) by Red Hat. The flaw specifically affects the security evaluation sequence in REST resources when using annotation-based security, where JSON payload deserialization occurs before security constraint evaluation. This behavior differs from configuration-based security, where security constraints are properly evaluated before JSON body processing (NVD, Red Hat Advisory).

Impact

The vulnerability could potentially allow unauthorized access to REST resources, as security constraints are evaluated after the JSON payload is processed. This timing issue in the security check sequence could lead to security bypass in applications using annotation-based security for REST resources (NVD).

Mitigation and workarounds

Red Hat has released security updates to address this vulnerability in Quarkus versions 2.13.9.SP1 and 3.2.9.SP1. Users are advised to upgrade to these patched versions. For version 3.2.9.SP1, this corresponds to 3.2.9.Final-redhat-00004 in the Maven repository (Red Hat Advisory, Bugzilla).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-29847HIGH7.5
  • JavaJava
  • org.apache.linkis:linkis
NoYesJan 19, 2026
CVE-2026-1050MEDIUM6.9
  • JavaJava
  • net.risesoft:risenet-y9boot-support-platform-service
NoNoJan 17, 2026
CVE-2025-15104MEDIUM6.9
  • JavaScriptJavaScript
  • vnu-jar
NoNoJan 16, 2026
CVE-2025-59355MEDIUM6.5
  • JavaJava
  • org.apache.linkis:linkis-metadata
NoYesJan 19, 2026
CVE-2026-0858MEDIUM5.1
  • JavaJava
  • net.sourceforge.plantuml:plantuml
NoYesJan 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management