Quarkus: information leak in annotation
Published Mar 13, 2024
3.5
LOWCVSS 3.1
EPSS 0.60%
Description
A vulnerability was found in Quarkus. In certain conditions related to the CI process, git credentials could be inadvertently published, which could put the git repository at risk.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat build of Quarkus | affected |
|
No data.
No data.
Red Hat build of Quarkus 3.2.11.Final
io.quarkus/quarkus-kubernetes-deployment:3.2.11.Final-redhat-00001
Fixed · RHSA-2024:1662
Red Hat build of Quarkus
quarkus-kubernetes-deployment
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat build of Quarkus 3.2.11.Final | io.quarkus/quarkus-kubernetes-deployment:3.2.11.Final-redhat-00001 | Fixed | RHSA-2024:1662 |
| Red Hat build of Quarkus | quarkus-kubernetes-deployment | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Ensure that at least one of the preconditions is not present in your environment.
Red Hat statement
Three conditions are required to enable this vulnerability: 1) If you are in an environment where you have a token in the Git URL of the Quarkus project you are building 2) If you build with a Quarkus extension that generates a Kubernetes descriptor (for instance a Kubernetes or OpenShift extension) 3) If this descriptor is automatically published as a build artifact (such as GitHub Actions artifacts) Due to these combined restrictions, which are all beyond an attackers control, there is limited opportunity for exploitation. Therefore, the security impact is rated Moderate.
Red Hat mitigation
Ensure that at least one of the preconditions is not present in your environment.
References (9)
- https://access.redhat.com/errata/RHSA-2024:1662 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-1979 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2266690 issue-trackingx_refsource_REDHATIssue Tracking
- https://github.com/advisories/GHSA-7g97-7r3c-5cc6 Advisory
- https://github.com/quarkusio/quarkus/commit/3a3b0d739222a2e476e085a955cfa090739f5924
- https://github.com/quarkusio/quarkus/commit/5bc05ee35365a905f0e9e37f248c38688a81caaf
- https://github.com/quarkusio/quarkus/issues/38055
- https://nvd.nist.gov/vuln/detail/CVE-2024-1979
- https://www.cve.org/CVERecord?id=CVE-2024-1979
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2024:1662 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2024-1979 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2266690 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://github.com/advisories/GHSA-7g97-7r3c-5cc6 | Advisory | |
| https://github.com/quarkusio/quarkus/commit/3a3b0d739222a2e476e085a955cfa090739f5924 | ||
| https://github.com/quarkusio/quarkus/commit/5bc05ee35365a905f0e9e37f248c38688a81caaf | ||
| https://github.com/quarkusio/quarkus/issues/38055 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2024-1979 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-1979 |
Change history (0)
No recorded changes yet.