VYPR
Medium severity5.3NVD Advisory· Published Dec 6, 2023· Updated Aug 4, 2026

CVE-2023-6393

CVE-2023-6393

Description

A flaw was found in the Quarkus Cache Runtime. When request processing utilizes a Uni cached using @CacheResult and the cached Uni reuses the initial "completion" context, the processing switches to the cached Uni instead of the request context. This is a problem if the cached Uni context contains sensitive information, and could allow a malicious user to benefit from a POST request returning the response that is meant for another user, gaining access to sensitive data.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
io.quarkus:quarkus-cacheMaven
>= 3.3.0.CR1, < 3.5.23.5.2
io.quarkus:quarkus-cacheMaven
>= 3.2.0.CR1, < 3.2.9.Final3.2.9.Final

Affected products

4
  • Red Hat/Red Hat build of Quarkus 2.13.9.Finalv5
    cpe:/a:redhat:quarkus:2.13
    Range: 2.13.9.Final-redhat-00002
  • Red Hat/Build Of Quarkuscpe-rescue2 versions
    cpe:/a:redhat:quarkus:3+ 1 more
    • cpe:/a:redhat:quarkus:3
    • cpe:2.3:a:redhat:build_of_quarkus:-:*:*:*:*:*:*:*
  • ghsa-coords
    Range: >= 3.3.0.CR1, < 3.5.2

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.