CVE-2024-2700
CVSS 3.1 Score 7.0 of 10 (high)
Details
Summary
CVE-2024-2700: Quarkus' quarkus-core component unintentionally captures local environment variables from the Quarkus namespace during application building. These variables, which may include sensitive settings or test configurations, are incorporated into the final application if they originate from the `quarkus.*` namespace. This can lead to potentially dangerous behavior if the application does not override these captured values. The vulnerability affects only configuration properties within the `quarkus.*` namespace, and application-specific properties remain unaffected.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.