CVE-2023-1584
Estado: ModificadaAlta (7.5)—
A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an insecure HTTP protocol is used, which can allow attackers to access sensitive user data directly from the ID token or by using the access token to access user data from OIDC provider services. Please note that passwords are not stored in access tokens.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.96%
- Percentil entre todas las CVEs puntuadas: 60
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-200
- NVD-CWE-noinfo
Referencias
- https://access.redhat.com/errata/RHSA-2023:3809
- https://access.redhat.com/errata/RHSA-2023:7653
- https://access.redhat.com/security/cve/CVE-2023-1584
- https://bugzilla.redhat.com/show_bug.cgi?id=2180886
- https://github.com/quarkusio/quarkus/pull/32192
- https://github.com/quarkusio/quarkus/pull/33414
- https://access.redhat.com/errata/RHSA-2023:3809
- https://access.redhat.com/errata/RHSA-2023:7653
- https://access.redhat.com/security/cve/CVE-2023-1584
- https://bugzilla.redhat.com/show_bug.cgi?id=2180886
- https://github.com/quarkusio/quarkus/pull/32192
- https://github.com/quarkusio/quarkus/pull/33414
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-1584",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"versions": [
{
"status": "unaffected",
"version": "3.1.0.CR1"
}
],
"packageName": "quarkus-oidc",
"collectionURL": "https://mvnrepository.com/artifact/io.quarkus"
},
{
"cpes": [
"cpe:/a:redhat:quarkus:2.13"
],
"vendor": "Red Hat",
"product": "Red Hat build of Quarkus 2.13.8.Final",
"versions": [
{
"status": "unaffected",
"version": "2.13.8.Final-redhat-00004",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "io.quarkus/quarkus-oidc",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:service_registry:2.5"
],
"vendor": "Red Hat",
"product": "RHINT Service Registry 2.5.4 GA",
"packageName": "quarkus-oidc",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-10-04T11:15:09.770",
"references": [
{
"url": "https://access.redhat.com/errata/RHSA-2023:3809",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2023:7653",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2023-1584",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2180886",
"tags": [
"Issue Tracking",
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/quarkusio/quarkus/pull/32192",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/quarkusio/quarkus/pull/33414",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2023:3809",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://access.redhat.com/errata/RHSA-2023:7653",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2023-1584",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2180886",
"tags": [
"Issue Tracking",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/quarkusio/quarkus/pull/32192",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/quarkusio/quarkus/pull/33414",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an insecure HTTP protocol is used, which can allow attackers to access sensitive user data directly from the ID token or by using the access token to access user data from OIDC provider services. Please note that passwords are not stored in access tokens."
},
{
"lang": "es",
"value": "Se encontró un defecto en Quarkus. Quarkus OIDC puede filtrar tanto ID como tokens de acceso en el flujo del código de autorización cuando se utiliza un protocolo HTTP inseguro, lo que puede permitir a los atacantes acceder a datos confidenciales del usuario directamente desde el token de ID o utilizando el token de acceso para acceder a los datos del usuario desde los servicios del proveedor OIDC. . Tenga en cuenta que las contraseñas no se almacenan en tokens de acceso."
}
],
"lastModified": "2026-06-17T05:28:18.747",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "77E10BE3-2878-4766-81B6-F20A28986885",
"versionEndExcluding": "2.13.8"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}