CVE-2023-6394
Executive Summary
CVE-2023-6394 exposes a Quarkus flaw where WebSocket GraphQL requests lacking role-based permissions bypass authentication on secured endpoints, enabling attackers to access data and functions beyond intended API permissions.
Authoritative CVE Metadata - CVSS Base Score: 7.4 (HIGH) - Published: 2023-12-09T02:15:06.747 - Last Modified: 2026-09-29T10:17:10.133
Original Description: A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.
"You, yourself, as much as anybody in the entire universe, deserve your love and affection."
— Buddha