CVE-2023-2974

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/07/2023
Last modified:
07/11/2023

Description

A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force the selection of the weaker supported TLS protocol.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:build_of_quarkus:*:*:*:*:*:*:*:* 2.13.8 (excluding)