THREAT OPS › Threat News › [NVD] CVE-2025-1247 (HIGH 8.3) — A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.
[NVD] CVE-2025-1247 (HIGH 8.3) — A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.
CVE-2025-1247 CVSS: 8.3 HIGH Published: 2025-02-13T14:16:18.400
A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.
Indicators of compromise
- CVE-2025-1247cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-1247