Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-1979

Опубликовано: 05 янв. 2024
Источник: redhat
CVSS3: 3.5

Описание

A vulnerability was found in Quarkus. In certain conditions related to the CI process, git credentials could be inadvertently published, which could put the git repository at risk.

Отчет

Three conditions are required to enable this vulnerability:

  1. If you are in an environment where you have a token in the Git URL of the Quarkus project you are building
  2. If you build with a Quarkus extension that generates a Kubernetes descriptor (for instance a Kubernetes or OpenShift extension)
  3. If this descriptor is automatically published as a build artifact (such as GitHub Actions artifacts) Due to these combined restrictions, which are all beyond an attackers control, there is limited opportunity for exploitation. Therefore, the security impact is rated Moderate.

Меры по смягчению последствий

Ensure that at least one of the preconditions is not present in your environment.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Quarkusio.quarkus/quarkus-kubernetes-deploymentWill not fix
Red Hat build of Quarkus 3.2.11.Finalio.quarkus/quarkus-kubernetes-deploymentFixedRHSA-2024:166203.04.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2266690quarkus: information leak in annotation

3.5 Low

CVSS3

Связанные уязвимости

CVSS3: 3.5
nvd
почти 2 года назад

A vulnerability was found in Quarkus. In certain conditions related to the CI process, git credentials could be inadvertently published, which could put the git repository at risk.

CVSS3: 3.5
github
почти 2 года назад

In Quarkus, git credentials could be inadvertently published

3.5 Low

CVSS3

Уязвимость CVE-2024-1979