The vendor explicitly identifies these products as affected by this CVE.
- exploit-intelligence-tech-preview/agent-client-rhel9 as a component of Exploit Intelligence
- quarkus-oidc as a component of Red Hat build of Apicurio Registry 3
- quarkus-oidc as a component of Red Hat build of Quarkus
- Summary
- A flaw was found in Quarkus OIDC. A shared token-introspection cache can be exploited by a remote attacker to bypass authentication across different tenants. This allows unauthorized access to resources or data, leading to a cross-tenant authentication bypass.
- Remediation
- Affected
