CVE-2022-2466
CRITICAL9.8EPSS 12.8%Quarkus does not terminate HTTP requests header context
發布日:2022/9/1修改日:2023/11/8
描述
Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavior. This issue was fixed in version 2.10.4Final.
受影響套件(1)
- Maven/io.quarkus:quarkus-core-parent>= 2.10.0, < 2.10.4
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |