CVE-2023-0044: Cross-Site Request Forgery (CSRF)
If the Quarkus Form Authentication session cookie Path attribute is set to /
then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented with the Quarkus CSRF Prevention feature.
References
Detect and mitigate CVE-2023-0044 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →