Incorrect Authorization The advisory has been revoked - it doesn't affect any version of package io.quarkus:quarkus-smallrye-graphql-client-parent  (opens in a new tab)


Threat Intelligence

EPSS
0.15% (53rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-IOQUARKUS-6117640
  • published12 Dec 2023
  • disclosed9 Dec 2023
  • creditUnknown

Introduced: 9 Dec 2023

CVE-2023-6394  (opens in a new tab)
CWE-696  (opens in a new tab)

How to fix?

Upgrade io.quarkus:quarkus-smallrye-graphql-client-parent to version 2.13.9.Final, 3.5.3 or higher.

Amendment

This was deemed not a vulnerability.

Overview

Affected versions of this package are vulnerable to Incorrect Authorization via the handling of websocket requests that lack role-based permissions for GraphQL operations. An attacker can access information and execute functionality that should be restricted by exploiting the lack of authentication checks on secured endpoints.