
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-6267 is a security vulnerability discovered in Quarkus, affecting the JSON payload processing in REST resources. The vulnerability was disclosed on January 25, 2024, and affects Quarkus versions up to 2.13.9 and versions from 3.0.0 up to 3.2.9. The flaw occurs when annotation-based security is used to secure a REST resource, where the JSON body is processed (deserialized) before security constraints are evaluated and applied (NVD).
The vulnerability has been assigned a CVSS v3.1 base score of 9.8 (CRITICAL) by NIST and 8.6 (HIGH) by Red Hat. The flaw specifically affects the security evaluation sequence in REST resources when using annotation-based security, where JSON payload deserialization occurs before security constraint evaluation. This behavior differs from configuration-based security, where security constraints are properly evaluated before JSON body processing (NVD, Red Hat Advisory).
The vulnerability could potentially allow unauthorized access to REST resources, as security constraints are evaluated after the JSON payload is processed. This timing issue in the security check sequence could lead to security bypass in applications using annotation-based security for REST resources (NVD).
Red Hat has released security updates to address this vulnerability in Quarkus versions 2.13.9.SP1 and 3.2.9.SP1. Users are advised to upgrade to these patched versions. For version 3.2.9.SP1, this corresponds to 3.2.9.Final-redhat-00004 in the Maven repository (Red Hat Advisory, Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."