If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented with the Quarkus CSRF Prevention feature.
2023-02-23T20:15:12.823
2024-11-21T07:36:27.050
Modified
CVSSv3.1: 6.1 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | quarkus | quarkus | < 2.13.7 | Yes |
| Application | redhat | build_of_quarkus | - | Yes |