CVE-2024-2700

CVSS 3.1 Score 7.0 of 10 (high)

Details

Published Apr 4, 2024
Updated: Jul 25, 2024
CWE ID 526

Summary

CVE-2024-2700: Quarkus' quarkus-core component unintentionally captures local environment variables from the Quarkus namespace during application building. These variables, which may include sensitive settings or test configurations, are incorporated into the final application if they originate from the `quarkus.*` namespace. This can lead to potentially dangerous behavior if the application does not override these captured values. The vulnerability affects only configuration properties within the `quarkus.*` namespace, and application-specific properties remain unaffected.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share