Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p62q-5483-h57v

Опубликовано: 15 нояб. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.7

Описание

Quarkus does not properly sanitize artifacts created from its use of the Gradle plugin, allowing certain build system information to remain

A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing certain build system information to remain. This flaw allows an attacker to access potentially sensitive information from the build system within the application.

Пакеты

Наименование

io.quarkus:quarkus-project

maven
Затронутые версииВерсия исправления

>= 3.0.0.CR1, <= 3.5.1

Отсутствует

EPSS

Процентиль: 55%
0.00815
Низкий

7.7 High

CVSS3

Дефекты

CWE-526

Связанные уязвимости

CVSS3: 7.7
redhat
почти 3 года назад

A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing certain build system information to remain. This flaw allows an attacker to access potentially sensitive information from the build system within the application.

CVSS3: 7.7
nvd
почти 3 года назад

A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing certain build system information to remain. This flaw allows an attacker to access potentially sensitive information from the build system within the application.

CVSS3: 7.7
fstec
почти 3 года назад

Уязвимость плагина Gradle Java-фреймворка Quarkus, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 55%
0.00815
Низкий

7.7 High

CVSS3

Дефекты

CWE-526