High severity8.1NVD Advisory· Published Sep 20, 2023· Updated Aug 4, 2026
CVE-2023-4853
CVE-2023-4853
Description
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.quarkus:quarkus-vertx-httpMaven | < 2.16.11.Final | 2.16.11.Final |
io.quarkus:quarkus-vertx-httpMaven | >= 3.0.0, < 3.2.6.Final | 3.2.6.Final |
io.quarkus:quarkus-vertx-httpMaven | >= 3.3.0, < 3.3.3 | 3.3.3 |
io.quarkus:quarkus-undertowMaven | < 2.16.11.Final | 2.16.11.Final |
io.quarkus:quarkus-undertowMaven | >= 3.0.0, < 3.2.6.Final | 3.2.6.Final |
io.quarkus:quarkus-undertowMaven | >= 3.3.0, < 3.3.3 | 3.3.3 |
io.quarkus:quarkus-csrf-reactiveMaven | < 2.16.11.Final | 2.16.11.Final |
io.quarkus:quarkus-csrf-reactiveMaven | >= 3.0.0, < 3.2.6.Final | 3.2.6.Final |
io.quarkus:quarkus-csrf-reactiveMaven | >= 3.3.0, < 3.3.3 | 3.3.3 |
io.quarkus:quarkus-keycloak-authorizationMaven | < 2.16.11.Final | 2.16.11.Final |
io.quarkus:quarkus-keycloak-authorizationMaven | >= 3.0.0, < 3.2.6.Final | 3.2.6.Final |
io.quarkus:quarkus-keycloak-authorizationMaven | >= 3.3.0, < 3.3.3 | 3.3.3 |
Affected products
29- Red Hat/RHINT Camel-K-1.10.2v5cpe:/a:redhat:camel_k:1
- Red Hat/Red Hat Camel Extensions for Quarkus 2.13.3-1v5cpe:/a:redhat:camel_quarkus:2.13
- cpe:/a:redhat:jboss_enterprise_bpms_platform:7
- Red Hat/RHPAM 7.13.4 asyncv5cpe:/a:redhat:jboss_enterprise_bpms_platform:7.13
cpe:/a:redhat:openshift_serverless:1.30::el8+ 3 more
- cpe:/a:redhat:openshift_serverless:1.30::el8range: 1.30.0-6
- cpe:/a:redhat:serverless:1.0::el8range: 0:1.9.2-3.el8
- cpe:2.3:a:redhat:openshift_serverless:-:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_serverless:1.0:*:*:*:*:*:*:*
cpe:/a:redhat:optaplanner:::el6+ 1 more
- cpe:/a:redhat:optaplanner:::el6
- cpe:2.3:a:redhat:build_of_optaplanner:8.0:*:*:*:*:*:*:*
- Red Hat/Red Hat build of Quarkus 2.13.8.SP2v5cpe:/a:redhat:quarkus:2.13Range: 2.13.8.Final-redhat-00005
- Red Hat/RHEL-8 based Middleware Containersv5cpe:/a:redhat:rhosemc:1.0::el8Range: 7.13.4-3
- Red Hat/RHINT Service Registry 2.5.4 GAv5cpe:/a:redhat:service_registry:2.5
- cpe:2.3:a:redhat:build_of_quarkus:*:*:*:*:text-only:*:*:*Range: >=2.13.0,<2.13.8
- cpe:2.3:a:redhat:decision_manager:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:integration_camel_quarkus:-:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:integration_service_registry:-:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_middleware:1:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_middleware_text-only_advisories:1.0:*:*:*:*:middleware:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.10:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:redhat:openshift_container_platform:4.10:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.11:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.12:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:process_automation_manager:7.0:*:*:*:*:*:*:*
- ghsa-coords4 versionspkg:maven/io.quarkus/quarkus-csrf-reactivepkg:maven/io.quarkus/quarkus-keycloak-authorizationpkg:maven/io.quarkus/quarkus-undertowpkg:maven/io.quarkus/quarkus-vertx-http
< 2.16.11.Final+ 3 more
- (no CPE)range: < 2.16.11.Final
- (no CPE)range: < 2.16.11.Final
- (no CPE)range: < 2.16.11.Final
- (no CPE)range: < 2.16.11.Final
Patches
Vulnerability mechanics
References
16- access.redhat.com/security/vulnerabilities/RHSB-2023-002nvdExploitMitigationTechnical DescriptionVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2023:5170nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2023:5310nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2023:5337nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2023:5446nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2023:5479nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2023:5480nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2023:6107nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2023:6112nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2023:7653nvdVendor AdvisoryWEB
- access.redhat.com/security/cve/CVE-2023-4853nvdMitigationVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-4f4r-wgv2-jjvgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-4853ghsaADVISORY
- access.redhat.com/articles/11258ghsaWEB
- github.com/quarkusio/quarkus/issues/35785ghsaWEB
News mentions
0No linked articles in our index yet.