CVE-2022-4147
Quarkus CORS filter allows simple GET and POST requests with an invalid Origin to proceed
7.5
HIGH
CVSS 3.1
EPSS 0.46%
Description
Quarkus CORS filter allows simple GET and POST requests with invalid Origin to proceed. Simple GET or POST requests made with XMLHttpRequest are the ones which have no event listeners registered on the object returned by the XMLHttpRequest upload property and have no ReadableStream object used in the request.
How to fix CVE-2022-4147
To remediate CVE-2022-4147, upgrade the affected package to a fixed version below.
- —upgrade to 2.14.2.Final or later
Is CVE-2022-4147 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 2.14.0.CR1, < 2.14.2.Final
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |