Quarkus Improper Handling of Insufficient Permissions or Privileges and Improper Handling of Exceptional Conditions vulnerability
High severity
GitHub Reviewed
Published
Jan 25, 2024
to the GitHub Advisory Database
•
Updated Feb 17, 2024
Package
Affected versions
< 2.13.9.Final
>= 3.0.0.Final, < 3.2.9.Final
Patched versions
2.13.9.Final
3.2.9.Final
Description
Published by the National Vulnerability Database
Jan 25, 2024
Published to the GitHub Advisory Database
Jan 25, 2024
Reviewed
Jan 31, 2024
Last updated
Feb 17, 2024
A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource may consume is being processed (deserialized) prior to the security constraints being evaluated and applied. This does not happen with configuration based security.
References