Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. io.quarkus/quarkus-vertx-http
  4. ›
  5. CVE-2022-4147

CVE-2022-4147: Quarkus CORS filter allows simple GET and POST requests with an invalid Origin to proceed

December 6, 2022

Quarkus CORS filter allows simple GET and POST requests with invalid Origin to proceed. Simple GET or POST requests made with XMLHttpRequest are the ones which have no event listeners registered on the object returned by the XMLHttpRequest upload property and have no ReadableStream object used in the request.

References

  • access.redhat.com/security/cve/CVE-2022-4147
  • bugzilla.redhat.com/show_bug.cgi?id=2148867
  • github.com/advisories/GHSA-9895-g6x5-xwcp
  • nvd.nist.gov/vuln/detail/CVE-2022-4147
  • quarkus.io/blog/quarkus-2-14-2-final-released/

Code Behaviors & Features

Detect and mitigate CVE-2022-4147 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.13.5.final, all versions starting from 2.14.0.cr1 before 2.14.2.final

Fixed versions

  • 2.13.5.Final
  • 2.14.2.Final

Solution

Upgrade to versions 2.13.5.Final, 2.14.2.Final or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-1026

Source file

maven/io.quarkus/quarkus-vertx-http/CVE-2022-4147.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:16:16 +0000.