CVE-2024-1979
Quarkus: information leak in annotation
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 3.5EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
13 Mar 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability was found in Quarkus. In certain conditions related to the CI process, git credentials could be inadvertently published, which could put the git repository at risk.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
Affected products
quarkusRed Hat · Red Hat build of QuarkusRed Hat · Red Hat build of Quarkus 3.2.11.FinalWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →