ID |
CVE-2025-49574
|
Sažetak |
Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. In versions prior to 3.24.0, there is a potential data leak when duplicating a duplicated context. Quarkus extensively uses the Vert.x duplicated context to implement context propagation. With the new semantic data from one transaction can leak to the data from another transaction. From a Vert.x point of view, this new semantic clarifies the behavior. A significant amount of data is stored in the duplicated context, including request scope, security details, and metadata. Duplicating a duplicated context is rather rare and is only done in a few places. This issue has been patched in version 3.24.0. |
Reference |
|
CVSS |
Base: | 6.4 |
Impact: | 5.2 |
Exploitability: | 1.2 |
|
Pristup |
Vektor | Složenost | Autentikacija |
ADJACENT_NETWORK |
HIGH |
LOW |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
HIGH |
HIGH |
NONE |
|
CVSS vektor |
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
Zadnje važnije ažuriranje |
23-06-2025 - 20:16 |
Objavljeno |
23-06-2025 - 20:15 |