Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 10, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 10, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 10, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 10, 2025

      Diablo 4 gives you the chance to win a Mother’s Day candle and express your love (or hatred) with “Mother’s Judgement”

      May 10, 2025

      Here’s how to speedrun the Call of Duty: Black Ops 6 and Warzone Blaze of Glory event as fast as possible

      May 10, 2025

      How to prevent your PC from locking automatically on Windows 11

      May 10, 2025

      Frostpunk 2 heats up with a free “major content update” that overhauls the survival city builder’s core gameplay

      May 10, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Laravel Routing

      May 10, 2025
      Recent

      Laravel Routing

      May 10, 2025

      Big Node, VS Code, and Mantine updates

      May 9, 2025

      Prepare for Contact Center Week with Colleen Eager

      May 9, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Diablo 4 gives you the chance to win a Mother’s Day candle and express your love (or hatred) with “Mother’s Judgement”

      May 10, 2025
      Recent

      Diablo 4 gives you the chance to win a Mother’s Day candle and express your love (or hatred) with “Mother’s Judgement”

      May 10, 2025

      Here’s how to speedrun the Call of Duty: Black Ops 6 and Warzone Blaze of Glory event as fast as possible

      May 10, 2025

      How to prevent your PC from locking automatically on Windows 11

      May 10, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Security»Common Vulnerabilities and Exposures (CVEs)»CVE-2024-12225 – Quarkus WebAuthn Default Endpoints Information Disclosure and Authentication Bypass

    CVE-2024-12225 – Quarkus WebAuthn Default Endpoints Information Disclosure and Authentication Bypass

    May 6, 2025

    CVE ID : CVE-2024-12225

    Published : May 6, 2025, 8:15 p.m. | 2 hours ago

    Description : A vulnerability was found in Quarkus in the quarkus-security-webauthn module. The Quarkus WebAuthn module publishes default REST endpoints for registering and logging users in while allowing developers to provide custom REST endpoints. When developers provide custom REST endpoints, the default endpoints remain accessible, potentially allowing attackers to obtain a login cookie that has no corresponding user in the Quarkus application or, depending on how the application is written, could correspond to an existing user that has no relation with the current attacker, allowing anyone to log in as an existing user by just knowing that user’s user name.

    Severity: 9.1 | CRITICAL

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleCVE-2025-47256 – Libxmp Buffer Overflow Vulnerability
    Next Article I can’t believe this long-lost Halo level has finally been found — and you might be able to play it soon

    Related Posts

    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-4536 – Gosuncn Technology Group Audio-Visual Integrated Management Platform Remote Information Disclosure

    May 11, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-4537 – RuoYi-Vue Cleartext Storage of Sensitive Information in Cookie

    May 11, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    13 Best Free and Open Source Linux Video Converters

    Linux

    How Smooth Is Attention?

    Development

    CVE-2025-42600 – Meon KYC Brute Force OTP Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-32890 – goTenna Mesh Plaintext Injection Vulnerability

    Common Vulnerabilities and Exposures (CVEs)
    GetResponse

    Highlights

    RustoBot Botnet Exploits Router Flaws in Sophisticated Attacks

    April 21, 2025

    RustoBot Botnet Exploits Router Flaws in Sophisticated Attacks

    FortiGuard Labs recently discovered RustoBot, written in Rust, a memory-safe language known for its performance and security, a sophisticated botnet exploiting vulnerabilities in TOTOLINK and DrayTek …
    Read more

    Published Date:
    Apr 22, 2025 (2 hours, 26 minutes ago)

    Vulnerabilities has been mentioned in this article.

    CVE-2024-12987

    CVE-2022-26187

    CVE-2022-26210

    I can’t believe I’m enjoying Call of Duty: Warzone’s new weed-themed limited time game mode this much

    May 6, 2025

    Gibbs Diffusion (GDiff): A New Bayesian Blind Denoising Method with Applications in Image Denoising and Cosmology

    July 3, 2024

    Meta Launches LlamaFirewall Framework to Stop AI Jailbreaks, Injections, and Insecure Code

    April 30, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.