{"id":"CVE-2022-0981","details":"A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another in RestEasy Reactive. This flaw allows a low-privileged user to perform operations on the database with a different set of privileges than intended.","modified":"2026-08-12T03:51:25.321422744Z","published":"2022-03-23T19:46:41Z","database_specific":{"cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/0xxx/CVE-2022-0981.json","cna_assigner":"redhat"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/0xxx/CVE-2022-0981.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0981"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2062520"},{"type":"REPORT","url":"https://github.com/quarkusio/quarkus/issues/23269"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/quarkusio/quarkus","events":[{"introduced":"ea4ef3d5edf4dd376a045033195dfd9c1adafbb0"},{"fixed":"ea4ef3d5edf4dd376a045033195dfd9c1adafbb0"}],"database_specific":{"cpe":"cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"quarkus 2.7.1.Final"},{"last_affected":"quarkus 2.7.1.Final"},{"introduced":"0"},{"fixed":"2.7.1"}],"source":["AFFECTED_FIELD","CPE_RANGE"]}}],"versions":["quarkus 2.7.1.Final"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-0981.json"}}],"schema_version":"1.9.0"}