Back

LOW

Quarkus: information leak in annotation

Published Mar 13, 2024

Description

A vulnerability was found in Quarkus. In certain conditions related to the CI process, git credentials could be inadvertently published, which could put the git repository at risk.

Affected products

Remediation

Vendor solution

Ensure that at least one of the preconditions is not present in your environment.

Red Hat statement

Three conditions are required to enable this vulnerability: 1) If you are in an environment where you have a token in the Git URL of the Quarkus project you are building 2) If you build with a Quarkus extension that generates a Kubernetes descriptor (for instance a Kubernetes or OpenShift extension) 3) If this descriptor is automatically published as a build artifact (such as GitHub Actions artifacts) Due to these combined restrictions, which are all beyond an attackers control, there is limited opportunity for exploitation. Therefore, the security impact is rated Moderate.

Red Hat mitigation

Ensure that at least one of the preconditions is not present in your environment.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 13, 2024
Updated Aug 4, 2026
Reserved Feb 28, 2024
CISA Vulnrichment
Updated Apr 3, 2024
NVD
Status Deferred
Modified Aug 4, 2026
Red Hat
Severity Moderate
Public date Jan 5, 2024
GHSA-7G97-7R3C-5CC6