Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3250 | A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions. |
Github GHSA |
GHSA-mvc8-6ffp-jrx5 | Authorization bypass in Quarkus |
Tue, 24 Mar 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-551 |
Wed, 25 Feb 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-551 |
Sat, 23 Nov 2024 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-03-24T11:28:00.390Z
Reserved: 2023-11-30T04:05:52.129Z
Link: CVE-2023-6394
Updated: 2024-08-02T08:28:21.766Z
Status : Modified
Published: 2023-12-09T02:15:06.747
Modified: 2026-03-24T12:16:10.450
Link: CVE-2023-6394
OpenCVE Enrichment
No data.
EUVD
Github GHSA