216.73.216.133

CVE-2025-49574

· Published 23/06/2025 20:15 · Modified 23/06/2025 20:16

Labels: CVE-2025-49574 2025-06-23CVE-2025-49574CWE-668[email protected]

Essential information

Published
23/06/2025 20:15
Modified
23/06/2025 20:16
Author
Creator
CVSS
6.4 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

CVSS metrics

Description

Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. In versions prior to 3.24.0, there is a potential data leak when duplicating a duplicated context. Quarkus extensively uses the Vert.x duplicated context to implement context propagation. With the new semantic data from one transaction can leak to the data from another transaction. From a Vert.x point of view, this new semantic clarifies the behavior. A significant amount of data is stored in the duplicated context, including request scope, security details, and metadata. Duplicating a duplicated context is rather rare and is only done in a few places. This issue has been patched in version 3.24.0.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
quarkus / quarkus cpe:2.3:a:quarkus:quarkus:<3.24.0:*:*:*:*:*:*:*

References