THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-1247 (HIGH 8.3) — A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.

[NVD] CVE-2025-1247 (HIGH 8.3) — A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.

lownvdPublished 2025-02-13

CVE-2025-1247 CVSS: 8.3 HIGH Published: 2025-02-13T14:16:18.400

A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-1247