PT-2024-21609 · Quarkus · Quarkus
Patrick Del Bello
·
Published
2024-04-04
·
Updated
2024-12-12
·
CVE-2024-2700
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Quarkus (affected versions not specified)
Description
A vulnerability was found in the quarkus-core component. Quarkus captures local environment variables from the Quarkus namespace during the application's build, and the resulting application inherits these values. Some local environment variables may have been set for testing purposes, such as dropping the database during application startup or trusting all TLS certificates. If these properties are configured using environment variables or the .env facility, they are captured into the built application, leading to potentially dangerous behavior if not overridden. This behavior only affects configuration properties from the
quarkus.* namespace.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quarkus