8.1
CVSSv3

CVE-2023-2974

Published: 04/07/2023 Updated: 07/11/2023
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force the selection of the weaker supported TLS protocol.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat build of quarkus

Vendor Advisories

Synopsis Moderate: Red Hat build of Quarkus 2138 release and security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat build of Quarkus Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a d ...
Description<!---->A vulnerability was found in quarkus-core This vulnerability occurs because the TLS protocol configured with quarkushttpsslprotocols is not enforced, and the client can force the selection of the weaker supported TLS protocolA vulnerability was found in quarkus-core This vulnerability occurs because the TLS protocol configur ...