GHSA-8j3x-w35r-rw4r · Severity: high · Ecosystem: maven — Quarkus Improper Handling of Insufficient Permissions or Privileges and Improper Handling of Exceptional Conditions vulnerability
A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource may consume is being processed (deserialized) prior to the security constraints being evaluated and applied. This does not happen with configuration based security.
Conclusion & alert: CVE-2023-6267 is rated Moderate Risk (59.3/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.67%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-07 | 0.60% | 0.67% | +0.07% |
| 2 | 2026-01-12 | 0.67% | 0.60% | -0.07% |
| 3 | 2025-06-15 | — | 0.67% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.6 | 3.1 | HIGH |
|
3.9 | 4.7 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
GHSA-8j3x-w35r-rw4r · Severity: high · Ecosystem: maven — Quarkus Improper Handling of Insufficient Permissions or Privileges and Improper Handling of Exceptional Conditions vulnerability
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2023-6267 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| quarkus | quarkus | < 2.13.9 | cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:* |
| quarkus | quarkus | >= 3.0.0, < 3.2.9 | cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:* |
| quarkus | quarkus | 2.13.9 | cpe:2.3:a:quarkus:quarkus:2.13.9:-:*:*:*:*:*:* |
| quarkus | quarkus | 3.2.9 | cpe:2.3:a:quarkus:quarkus:3.2.9:-:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://access.redhat.com/errata/RHSA-2024:0494 | |
| https://access.redhat.com/errata/RHSA-2024:0495 | |
| https://access.redhat.com/security/cve/CVE-2023-6267 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2251155 | Issue Tracking Vendor Advisory |