CVE-2023-5675 - CVE House
Back to Database
Status published Medium CVE-2023-5675

Quarkus: authorization flaw in quarkus resteasy reactive and classic when "quarkus.security.jaxrs.deny-unannotated-endpoints" or "quarkus.security.jaxrs.default-roles-allowed" properties are used.

Vulnerability Description

A flaw was found in Quarkus. When a Quarkus RestEasy Classic or Reactive JAX-RS endpoint has its methods declared in the abstract Java class or customized by Quarkus extensions using the annotation processor, the authorization of these methods will not be enforced if it is enabled by either 'quarkus.security.jaxrs.deny-unannotated-endpoints' or 'quarkus.security.jaxrs.default-roles-allowed' properties.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-5675

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • This issue was discovered by Michal Vavřík (Red Hat).

Affected Vendor

Affected Software

Red Hat build of Quarkus 2.13.9.Final, Red Hat build of Quarkus 3.2.9.Final, A-MQ Clients 2, Cryostat 2, OpenShift Serverless, Red Hat build of Apicurio Registry 2, Red Hat build of OptaPlanner 8, Red Hat Fuse 7, Red Hat Integration Camel K 1, Red Hat Integration Camel Quarkus 2, Red Hat JBoss Enterprise Application Platform 8, Red Hat Process Automation 7
Vulnerable Versions:
3.2.0, 3.6.0, 3.7.0, 3.8.0, 2.13.9.Final-redhat-00003, 3.2.9.Final-redhat-00003

Timeline

Official Publish: April 25th, 2024
Last Modified: November 20th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Weaknesses (CWE)