CVE-2025-1247

Publication date

2025-02-13 13:26:26

Family

redhat

State

PUBLISHED

Description

A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.