CVE-2023-0044
23.02.2023, 20:15
If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented with the Quarkus CSRF Prevention feature.
Vendor | Product | Version |
---|---|---|
quarkus | quarkus | 𝑥 < 2.13.7 |
redhat | build_of_quarkus | - |
𝑥
= Vulnerable software versions