3.17.4
5 years ago
11 days ago
Known vulnerabilities in the io.quarkus:quarkus-security-deployment package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
io.quarkus:quarkus-security-deployment is a Quarkus Security Deployment Affected versions of this package are vulnerable to Improper Authorization due to improper enforcement of authorization checks in JAX-RS endpoints that are either declared in abstract Java classes or customized by Quarkus extensions using the annotation processor. An attacker can bypass access restrictions by exploiting the lack of authorization on these endpoints. Note: A combination of 2 factors triggers it:
How to fix Improper Authorization? Upgrade | [0,3.2.10.Final)[3.3.0.CR1,3.6.8)[3.7.0.CR1,3.7.1) |