CVE advisoryCRITICAL
CVE-2023-6394
Quarkus GraphQL Websocket Authentication Bypass Allows Information Disclosure
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A vulnerability in the Quarkus framework allows unauthenticated attackers to bypass security controls on GraphQL operations received via WebSocket, potentially exposing sensitive information and functionality. This issue arises when role-based permissions are not explicitly defined for a GraphQL operation, leading the