CVE-2023-1584 PUBLISHED CVSS 7.5 HIGH

Quarkus OIDC can leak both ID and access tokens

EPSS 0.29% · 52.3th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.29%
52.3th percentile

Affected Products

VendorProductVersions
Red HatRHINT Service Registry 2.5.4 GA
Mavenio.quarkus:quarkus-oidc0, 3.0.0
3.1.0.CR1
quarkusquarkus0
Red HatRed Hat build of Quarkus 2.13.8.Final2.13.8.Final-redhat-00004

Timeline

References

Open in Interactive Console →