Quarkus does not properly sanitize artifacts created from its use of the Gradle plugin, allowing certain build system information to remain
High severity
GitHub Reviewed
Published
Nov 15, 2023
to the GitHub Advisory Database
•
Updated Nov 15, 2023
Package
Affected versions
>= 3.0.0.CR1, <= 3.5.1
Patched versions
None
Description
Published by the National Vulnerability Database
Nov 15, 2023
Published to the GitHub Advisory Database
Nov 15, 2023
Reviewed
Nov 15, 2023
Last updated
Nov 15, 2023
A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing certain build system information to remain. This flaw allows an attacker to access potentially sensitive information from the build system within the application.
References