CVE-2023-6394 - CVE House
Back to Database
Status published High CVE-2023-6394

Quarkus: graphql operations over websockets bypass

Vulnerability Description

A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-6394

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Red Hat build of Quarkus 2.13.9.Final, Red Hat build of Quarkus 3.2.9.Final
Vulnerable Versions:
2.13.9.Final-redhat-00002, 3.2.9.Final-redhat-00002

Timeline

Official Publish: December 9th, 2023
Last Modified: March 24th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses (CWE)