PT-2023-8561 · Quarkus · Quarkus
Chess Hazlett
·
Published
2023-10-23
·
Updated
2023-11-30
·
CVE-2023-5720
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Quarkus versions prior to 3.5.1
Quarkus versions prior to 3.2.8 (LTS)
Description
A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing certain build system information to remain. This flaw allows an attacker to access potentially sensitive information from the build system within the application. The vulnerability is related to the disclosure of information through environment variables.
Recommendations
For Quarkus versions prior to 3.5.1, update to Quarkus 3.5.1 or later to fix the issue.
For Quarkus versions prior to 3.2.8 (LTS), update to Quarkus 3.2.8 (LTS) or later to fix the issue.
As a temporary workaround, consider restricting access to the Gradle plugin until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quarkus