← voltar
CVE-2025-1247

Io.quarkus:quarkus-rest: quarkus rest endpoint request parameter leakage due to shared instance

CVSS 8.3 HIGHEPSS 0.7%CWE-488
A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →