VDB

CVE-2023-1584

CVE-2023-1584 PUBLISHED CVSS 7.5 HIGH

Quarkus OIDC can leak both ID and access tokens

EPSS 0.96% · 60.4th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.96%
60.4th percentile

Affected Products

VendorProductVersions
Red HatRHINT Service Registry 2.5.4 GA
Mavenio.quarkus:quarkus-oidc0, 3.0.0
3.1.0.CR1
quarkusquarkus0
Red HatRed Hat build of Quarkus 2.13.8.Final2.13.8.Final-redhat-00004

Timeline

  • Oct 4, 2023 CVE Published
  • Oct 5, 2023 EPSS Score
  • Nov 6, 2023 EPSS Score
  • Dec 9, 2023 EPSS Score
  • Jan 10, 2024 EPSS Score
  • Feb 11, 2024 EPSS Score
  • Mar 14, 2024 EPSS Score
  • Apr 16, 2024 EPSS Score
  • May 18, 2024 EPSS Score
  • Jun 19, 2024 EPSS Score
  • Jul 21, 2024 EPSS Score
  • Aug 23, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›