Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-5720

Опубликовано: 15 нояб. 2023
Источник: nvd
CVSS3: 7.7
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing certain build system information to remain. This flaw allows an attacker to access potentially sensitive information from the build system within the application.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:*
Версия от 3.0.1 (включая) до 3.2.8 (исключая)
cpe:2.3:a:quarkus:quarkus:3.0.0:candidate_release1:*:*:*:*:*:*
cpe:2.3:a:quarkus:quarkus:3.0.0:candidate_release2:*:*:*:*:*:*

EPSS

Процентиль: 55%
0.00815
Низкий

7.7 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-526
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.7
redhat
почти 3 года назад

A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing certain build system information to remain. This flaw allows an attacker to access potentially sensitive information from the build system within the application.

CVSS3: 7.7
github
почти 3 года назад

Quarkus does not properly sanitize artifacts created from its use of the Gradle plugin, allowing certain build system information to remain

CVSS3: 7.7
fstec
почти 3 года назад

Уязвимость плагина Gradle Java-фреймворка Quarkus, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 55%
0.00815
Низкий

7.7 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-526
NVD-CWE-noinfo