← back
CVE-2023-1584

Quarkus-oidc: id and access tokens leak via the authorization code flow

CVSS 7.5 HIGHEPSS 1.0%CWE-200
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.5EPSS 1.0%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
04 Oct 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an insecure HTTP protocol is used, which can allow attackers to access sensitive user data directly from the ID token or by using the access token to access user data from OIDC provider services. Please note that passwords are not stored in access tokens.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →