CVE-2025-1247
Red Hat Red Hat Build of Apache Camel 4.8 for Quarkus 3.15, Red Hat build of Quarkus 3.15.3.SP1, Red Hat build of Quarkus 3.8.6.SP3
A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.
- CVSS
- 8.3
- EPSS
- 0.76% 51.7% percentile
- CISA KEV
- Not listed
- Published
- 2025.02.13