CVE-2025-1247

CVSS 3.1 Score 8.3 of 10 (high)

Details

Published Feb 13, 2025
Updated: Mar 3, 2025
CWE ID 488

Summary

CVE-2025-1247 is a vulnerability affecting Quarkus REST that allows request parameters to leak between concurrent requests. This issue arises when endpoints utilize field injection without the appropriate CDI scope. An attacker who exploits this vulnerability can manipulate request data, potentially impersonating users or gaining unauthorized access to sensitive information. Quarkus users are advised to employ proper CDI scope configuration to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share