Bug 2245700 (CVE-2023-5720) - CVE-2023-5720 quarkus: build env information disclosure via gradle plugin
Summary: CVE-2023-5720 quarkus: build env information disclosure via gradle plugin
Keywords:
Status: NEW
Alias: CVE-2023-5720
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2244605
TreeView+ depends on / blocked
 
Reported: 2023-10-23 16:39 UTC by Chess Hazlett
Modified: 2023-11-15 09:44 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing certain build system information to remain. This flaw allows an attacker to access potentially sensitive information from the build system within the application.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Chess Hazlett 2023-10-23 16:39:01 UTC
Quarkus does not properly sanitize artifacts created from its use of the Gradle plugin, allowing certain build system information to remain. An attacker could use this flaw to access potentially sensitive information from the build system from within the application.

This affects versions 3.0.0.CR1 and later.


Note You need to log in before you can comment on or make changes to this bug.