Skip to content

CVE-2023-4586 in netty - is quarkus already dealing with this or is there a way to easily configure quarkus to be safe #36743

Discussion options

You must be logged in to vote

Verification of hostnames is enabled per default in quarkus:
https://quarkus.io/guides/all-config#quarkus-rest-client-config_quarkus.rest-client.verify-host

I interpret this as: CVE-2023-4586 is no issue for quarkus in default configuration.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by joergsesterhenn
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
1 participant