CVE-2023-6267
HighAdvisory
Published 25 Jan 2024In the index since 8 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.6
- base score, highest
- EPSS
- 0.007
- 52nd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 6
- of 17,781 indexed, latest versions
- Container images
- 5
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Quarkus Improper Handling of Insufficient Permissions or Privileges and Improper Handling of Exceptional Conditions vulnerability
Carried by container images the latest versions of 6 of 17,781 indexed charts deploy, on 5 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| resteasy-reactivemaven | 2.12.3.Final, 2.13.3.Final, 2.13.6.Final, 2.13.7.Final | 2.13.9.Final | 5 |
- OSV records
- GHSA-8j3x-w35r-rw4r
Charts affected
6 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| clowder2ncsaVerified publisher | 1.9.7 | 1 of 12See more | 37,373 |
| drogue-cloud-coredrogue-iotVerified publisher | 0.7.11 | 1 of 22See more | 55,666 |
| drogue-cloud-twindrogue-iotVerified publisher | 0.7.11 | 1 of 8See more | 6,915 |
| my-app-namemy-app-name | 0.0.2 | 1 of 1See more | 9,149 |
| simple-keycloaksikalabs | 0.1.0 | 1 of 1See more | 6,443 |
| keycloakxzaks | 2.2.0 | 1 of 1See more | 6,016 |
Container images carrying it
5 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | 054ef67eb7da | resteasy-reactive | 2.13.9.Final | 2 |
| bitnamilegacy/ | cb04e49e6eb1 | resteasy-reactive | 2.13.9.Final | 1 |
| viniciusfcf/ | bba8ee1b5cd5 | resteasy-reactive | 2.13.9.Final | 1 |
| quay.io/ | 8830f76112b6 | resteasy-reactive | 2.13.9.Final | 1 |
| quay.io/ | b8f2a453a17a | resteasy-reactive | 2.13.9.Final | 1 |