Medium severity5.3NVD Advisory· Published Dec 6, 2023· Updated Aug 4, 2026
CVE-2023-6393
CVE-2023-6393
Description
A flaw was found in the Quarkus Cache Runtime. When request processing utilizes a Uni cached using @CacheResult and the cached Uni reuses the initial "completion" context, the processing switches to the cached Uni instead of the request context. This is a problem if the cached Uni context contains sensitive information, and could allow a malicious user to benefit from a POST request returning the response that is meant for another user, gaining access to sensitive data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.quarkus:quarkus-cacheMaven | >= 3.3.0.CR1, < 3.5.2 | 3.5.2 |
io.quarkus:quarkus-cacheMaven | >= 3.2.0.CR1, < 3.2.9.Final | 3.2.9.Final |
Affected products
4- Red Hat/Red Hat build of Quarkus 2.13.9.Finalv5cpe:/a:redhat:quarkus:2.13Range: 2.13.9.Final-redhat-00002
cpe:/a:redhat:quarkus:3+ 1 more
- cpe:/a:redhat:quarkus:3
- cpe:2.3:a:redhat:build_of_quarkus:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
8- access.redhat.com/security/cve/CVE-2023-6393nvdVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-xfv5-jqgp-vqhjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-6393ghsaADVISORY
- access.redhat.com/errata/RHSA-2023:7700nvdWEB
- github.com/quarkusio/quarkus/commit/d9ace85caec2d8497b1a2c48b8d52bb163f04adfghsaWEB
- github.com/quarkusio/quarkus/issues/37078ghsaWEB
- github.com/quarkusio/quarkus/pull/37077ghsaWEB
News mentions
0No linked articles in our index yet.