{
  "threat_severity" : "Moderate",
  "public_date" : "2022-02-03T00:00:00Z",
  "bugzilla" : {
    "description" : "quarkus: privilege escalation vulnerability with RestEasy Reactive scope leakage in Quarkus",
    "id" : "2062520",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2062520"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.6",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L",
    "status" : "verified"
  },
  "cwe" : "CWE-863",
  "details" : [ "A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another in RestEasy Reactive. This flaw allows a low-privileged user to perform operations on the database with a different set of privileges than intended.", "A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another in RestEasy Reactive. This flaw allows a low-privileged user to perform operations on the database with a different set of privileges than intended." ],
  "statement" : "CodeReady Studio is no longer supported and therefore this flaw will not be addressed in CodeReady Studio. Please see https://developers.redhat.com/articles/2022/04/18/announcement-red-hat-codeready-studio-reaches-end-life for more information.",
  "acknowledgement" : "This issue was discovered by Sanne Grinovero (Red Hat).",
  "affected_release" : [ {
    "product_name" : "Red Hat build of Quarkus 2.7.5",
    "release_date" : "2022-05-18T00:00:00Z",
    "advisory" : "RHSA-2022:4623",
    "cpe" : "cpe:/a:redhat:quarkus:2.7",
    "package" : "quarkus"
  }, {
    "product_name" : "RHINT Camel-Q 2.7",
    "release_date" : "2022-07-19T00:00:00Z",
    "advisory" : "RHSA-2022:5606",
    "cpe" : "cpe:/a:redhat:camel_quarkus:2.7"
  }, {
    "product_name" : "RHINT Service Registry 2.3.0 GA",
    "release_date" : "2022-10-06T00:00:00Z",
    "advisory" : "RHSA-2022:6835",
    "cpe" : "cpe:/a:redhat:service_registry:2.3",
    "package" : "quarkus"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Integration Camel K 1",
    "fix_state" : "Affected",
    "package_name" : "quarkus",
    "cpe" : "cpe:/a:redhat:integration:1"
  }, {
    "product_name" : "Red Hat Integration Camel Quarkus 1",
    "fix_state" : "Affected",
    "package_name" : "quarkus",
    "cpe" : "cpe:/a:redhat:camel_quarkus:2"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2022-0981\nhttps://nvd.nist.gov/vuln/detail/CVE-2022-0981\nhttps://github.com/quarkusio/quarkus/issues/23269" ],
  "name" : "CVE-2022-0981",
  "csaw" : false
}