CVE-2025-1247
Raw vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:LSummary
CVE-2025-1247 is a high-severity Exposure of Data Element to Wrong Session (CWE-488) vulnerability. Its CVSS base score is 8.3 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Web Session Cookie (T1550.004); ranked in the top 48% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to AC-3 (Access Enforcement) and AC-4 (Information Flow Enforcement) — see the control section below for these in your framework.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
CVE-2025-1247, published on 2025-02-13, is a vulnerability in the Quarkus REST component that enables request parameters to leak between concurrent requests when endpoints employ field injection without a CDI scope. This flaw affects Quarkus applications using such configurations. It carries a CVSS v3.1 base score of 8.3 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L) and maps to CWE-488.
Attackers with low privileges (PR:L) can exploit this vulnerability remotely over the network with low attack complexity and no user interaction required. Exploitation permits manipulation of request data, user impersonation, or access to sensitive information, resulting in high confidentiality and integrity impacts alongside low availability impact.
Red Hat advisories, including errata RHSA-2025:1884, RHSA-2025:1885, and RHSA-2025:2067, address the issue with patches and updates. Further details on the vulnerability and mitigations are provided on the Red Hat security page for CVE-2025-1247 and Bugzilla entry 2345172.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-2099
Vulnerability Data
A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
AC-3 enforces access decisions that can be scoped to the correct session context.
AC-4 controls information flows between entities, reducing cross-session leakage.
SC-4 directly stops unintended transfer of data through shared resources that different sessions may access.
SC-39 isolates execution domains so one session cannot reach another's state or data.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Enforcing authorization policies and least privilege can prevent cross-session data exposure when session separation is treated as an access rule.
Protecting data-in-use directly addresses runtime leakage of session data to unauthorized contexts.
Logical access controls and segmentation can be applied to isolate session state within applications or environments.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing can detect the weakness but does not itself implement the preventive control.
Secure development lifecycle practices include session-management controls that prevent exposure of data to the wrong session.
Application security requirements explicitly call for proper session isolation and state management.
Secure system architecture principles require isolation of session state to avoid cross-session data leakage.
Secure coding standards mandate correct session handling to prevent exposure of data elements to the wrong session.
Information access restriction directly enforces session boundaries so data is not exposed to the wrong session.