CVE-2023-1584

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-1584
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-1584.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-1584
Aliases
Published
2023-10-04T11:15:09Z
Modified
2024-05-13T20:45:20Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an insecure HTTP protocol is used, which can allow attackers to access sensitive user data directly from the ID token or by using the access token to access user data from OIDC provider services. Please note that passwords are not stored in access tokens.

References

Affected packages

Git / github.com/quarkusio/quarkus

Affected ranges

Type
GIT
Repo
https://github.com/quarkusio/quarkus
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed