GHSA-phg3-gv66-q38x
HIGHCVE-2025-1247A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.
- Affected
- >= 3.9.0.CR1, < 3.15.3.1, < 3.8.6.1, >= 3.16.0.CR1, < 3.18.2
- Fixed in
- 3.15.3.1
- Weakness
- CWE-488
- Published
- 2025-02-13
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference