A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Mar 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:/a:redhat:camel_quarkus:3.15 | |
References |
|
Thu, 27 Feb 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:/a:redhat:quarkus:3.8::el8 | |
References |
|
Thu, 27 Feb 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:/a:redhat:quarkus:3.15::el8 | |
References |
|
Thu, 13 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 13 Feb 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | No description is available for this CVE. | A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information. |
Title | io.quarkus:quarkus-rest: Quarkus REST Endpoint Request Parameter Leakage Due to Shared Instance | Io.quarkus:quarkus-rest: quarkus rest endpoint request parameter leakage due to shared instance |
First Time appeared |
Redhat
Redhat camel Quarkus Redhat quarkus |
|
CPEs | cpe:/a:redhat:camel_quarkus:3 cpe:/a:redhat:quarkus:3 |
|
Vendors & Products |
Redhat
Redhat camel Quarkus Redhat quarkus |
|
References |
|
Wed, 12 Feb 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | No description is available for this CVE. | |
Title | io.quarkus:quarkus-rest: Quarkus REST Endpoint Request Parameter Leakage Due to Shared Instance | |
Weaknesses | CWE-488 | |
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|

Status: PUBLISHED
Assigner: redhat
Published: 2025-02-13T13:26:26.992Z
Updated: 2025-03-15T09:18:44.686Z
Reserved: 2025-02-12T09:43:11.716Z
Link: CVE-2025-1247

Updated: 2025-02-13T14:11:35.346Z

Status : Awaiting Analysis
Published: 2025-02-13T14:16:18.400
Modified: 2025-03-03T14:15:34.120
Link: CVE-2025-1247
