External risk intelligence

Quarkus GraphQL Websocket Authentication Bypass Allows Information Disclosure

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2023-6394

Quarkus is a framework commonly used to build web applications and APIs. Since this vulnerability affects GraphQL endpoints, which are frequently exposed as internet-facing services to facilitate communication between clients and backend systems, the vulnerable surface is commonly deployed in a manner that is reachable from the public internet.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security flaw has been identified in the Quarkus framework, impacting how GraphQL operations are handled. When specific permissions are not defined for a GraphQL request, the system may incorrectly process it without proper authentication, potentially allowing unauthorized access to information and functionalities. This issue is relevant for applications built using this framework.

  • Unauthenticated access to secured GraphQL features.
  • Affects applications using GraphQL via websockets.
  • Confirm exposure of unpermissioned GraphQL endpoints.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this by sending a crafted request over a WebSocket connection to a GraphQL endpoint. If the GraphQL operation lacks specific role-based permissions, the Quarkus framework incorrectly processes the request without requiring authentication, even if the endpoint is otherwise secured. This bypass allows unauthorized access to sensitive information and functionality.

  • Unauthenticated network access required.
  • WebSocket request to unsecured GraphQL operation.
  • Unauthorized access to information and functions.

Live Threat

Current exploitation, exposure, and threat context

When role-based permissions are not specified for a GraphQL operation, this vulnerability could allow an unauthenticated attacker to access sensitive information and execute unauthorized actions by sending a crafted WebSocket request.

  • Unauthorized access to system data.
  • Unauthenticated requests exploit the flaw.
  • Compromised information and unauthorized actions.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and platform teams are most likely responsible for addressing this vulnerability. The initial practical step is to identify all instances of the affected technology, determine their reachability and business criticality, and then confirm the accountable owner for each instance to plan remediation based on risk.

  • Confirm GraphQL API owner.
  • Verify unauthenticated access to operations.
  • Plan remediation or implement controls.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Quarkus?

Quarkus is a Kubernetes-native Java framework designed for building high-performance web applications and microservices. It is widely used by developers to create APIs, including those that leverage GraphQL, a query language for data fetching. Because it optimizes resource usage and start times, it serves as the backbone for many modern, scalable backend systems and distributed services.

What does CVE-2023-6394 mean in plain English?

This vulnerability is classified as Improper Authorization (CWE-862). It means the system fails to correctly verify a user's permissions when they interact with a specific part of the application. In this case, Quarkus skips the security check for certain GraphQL operations sent over WebSockets, allowing someone to access data or functions they are not supposed to see, even if they have not logged in.

How does an attacker trigger this vulnerability?

An attacker initiates the flaw by sending a specifically crafted request over a WebSocket connection to a GraphQL endpoint. The issue occurs when that specific GraphQL operation lacks defined role-based permissions. Simply visiting the application or sending standard HTTP requests that do not involve the vulnerable WebSocket GraphQL handling logic will not trigger this authentication bypass.

Is my application at risk?

Halo Surface Signal indicates that because this flaw impacts GraphQL endpoints—which are often used for client-to-server communication—the affected components are frequently deployed in internet-facing configurations. If your Quarkus-based service provides a GraphQL API exposed to the public internet, it is more likely to be reachable by external attackers compared to services kept strictly within an internal, private network.

What should I do if I run Quarkus?

Start by identifying all applications in your environment that utilize the Quarkus framework and specifically use GraphQL via WebSockets. Once you have an inventory, assess which of these endpoints are currently exposed to users. Coordinate with your development or platform teams to confirm if any GraphQL operations lack proper role-based access controls and prioritize applying available security updates to address the underlying framework flaw.

References