Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-5720

Опубликовано: 08 нояб. 2023
Источник: redhat
CVSS3: 7.7

Описание

A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing certain build system information to remain. This flaw allows an attacker to access potentially sensitive information from the build system within the application.

Отчет

No Red Hat products are affected by this flaw.

Дополнительная информация

Статус:

Important
Дефект:
CWE-526
https://bugzilla.redhat.com/show_bug.cgi?id=2245700quarkus: build env information disclosure via gradle plugin

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
nvd
около 2 лет назад

A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing certain build system information to remain. This flaw allows an attacker to access potentially sensitive information from the build system within the application.

CVSS3: 7.7
github
около 2 лет назад

Quarkus does not properly sanitize artifacts created from its use of the Gradle plugin, allowing certain build system information to remain

CVSS3: 7.7
fstec
больше 2 лет назад

Уязвимость плагина Gradle Java-фреймворка Quarkus, позволяющая нарушителю раскрыть защищаемую информацию

7.7 High

CVSS3