Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p62q-5483-h57v

Опубликовано: 15 нояб. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.7

Описание

Quarkus does not properly sanitize artifacts created from its use of the Gradle plugin, allowing certain build system information to remain

A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing certain build system information to remain. This flaw allows an attacker to access potentially sensitive information from the build system within the application.

Пакеты

Наименование

io.quarkus:quarkus-project

maven
Затронутые версииВерсия исправления

>= 3.0.0.CR1, <= 3.5.1

Отсутствует

EPSS

Процентиль: 85%
0.02423
Низкий

7.7 High

CVSS3

Дефекты

CWE-526

Связанные уязвимости

CVSS3: 7.7
redhat
около 2 лет назад

A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing certain build system information to remain. This flaw allows an attacker to access potentially sensitive information from the build system within the application.

CVSS3: 7.7
nvd
около 2 лет назад

A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing certain build system information to remain. This flaw allows an attacker to access potentially sensitive information from the build system within the application.

CVSS3: 7.7
fstec
больше 2 лет назад

Уязвимость плагина Gradle Java-фреймворка Quarkus, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 85%
0.02423
Низкий

7.7 High

CVSS3

Дефекты

CWE-526