Loading
A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.
Use CWE-862, Quarkus vendor hub and Quarkus product page to widen CVE-2023-6394 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-4116, CVE-2024-12225 and CVE-2023-6267 for nearby disclosures in the same product family.