PT-2024-21609 · Quarkus · Quarkus

Patrick Del Bello

·

Published

2024-04-04

·

Updated

2024-12-12

·

CVE-2024-2700

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Quarkus (affected versions not specified)
Description A vulnerability was found in the quarkus-core component. Quarkus captures local environment variables from the Quarkus namespace during the application's build, and the resulting application inherits these values. Some local environment variables may have been set for testing purposes, such as dropping the database during application startup or trusting all TLS certificates. If these properties are configured using environment variables or the .env facility, they are captured into the built application, leading to potentially dangerous behavior if not overridden. This behavior only affects configuration properties from the quarkus.* namespace.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-2700
GHSA-F8H5-V2VG-46RR

Affected Products

Quarkus