CVE-2023-6267
HIGHJSON Payload - Deserialization
Title source: llmDescription
A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource may consume is being processed (deserialized) prior to the security constraints being evaluated and applied. This does not happen with configuration based security.
References (4)
Scores
CVSS v3
8.6
EPSS
0.0067
EPSS Percentile
71.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Classification
CWE
CWE-755
Status
published
Affected Products (4)
quarkus/quarkus
< 2.13.9
quarkus/quarkus
quarkus/quarkus
io.quarkus.resteasy.reactive/resteasy-reactive
< 2.13.9.FinalMaven
Timeline
Published
Jan 25, 2024
Tracked Since
Feb 18, 2026