CVE-2023-0044
EUVD-2023-068923.02.2023, 20:15
If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented with the Quarkus CSRF Prevention feature.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| quarkus | quarkus | 𝑥 < 2.13.7 |
| redhat | build_of_quarkus | - |
𝑥
= Vulnerable software versions