-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| io.quarkus.resteasy.reactive:resteasy-reactive | maven | = 3.8.0.CR1 | 3.8.0 |
| io.quarkus.resteasy.reactive:resteasy-reactive | maven | >= 3.3.0.CR1, < 3.7.4 | 3.7.4 |
| io.quarkus.resteasy.reactive:resteasy-reactive | maven | < 3.2.11.Final | 3.2.11.Final |
The vulnerability stemmed from security checks being performed after serialization for inherited endpoints. The key issue was incorrect class name resolution in security annotation processing:
A Semantic Attack on Google Gemini - Read the Latest Research