← Vulnerability feed

Vulnerability record · CVE-2023-2974 · published 4 July 2023

CVE-2023-2974: Redhat build of quarkus vulnerability

Redhat · Build Of Quarkus

A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force the selection of the weaker supported TLS protocol.

8.1 CVSS 3.1 High EPSS 0.88% · top 42.2% CWE-757 · CWE-757
8.1CVSS 3.1 base score
0.88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force the selection of the weaker supported TLS protocol.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-2974 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed9.8CVE-2022-4116Redhat build of quarkus vulnerabilityA vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to…EPSS 33%9.1CVE-2023-6394Quarkus missing authorization vulnerabilityA flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operati…EPSS 0.81%8.1CVE-2023-4853Quarkus incorrect authorization vulnerabilityA flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulti…EPSS 1.4%7.8CVE-2022-1011Linux kernel use after free vulnerabilityA use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unaut…EPSS 1.2%7.5CVE-2023-1108Redhat build of quarkus vulnerabilityA flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, wh…EPSS 1.8%7.5CVE-2022-4492Redhat build of quarkus server-side request forgery (ssrf) vulnerabilityThe undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least…EPSS 0.60%7.5CVE-2022-1259Redhat build of quarkus uncontrolled resource consumption vulnerabilityA flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of servic…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2023-2974), CISA KEV, FIRST EPSS (scores of 2026-10-06). This page is refreshed as NVD updates the record.