CVE-2023-5720: Quarkus: build env information disclosure via gradle plugin
A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing certain build system information to remain. This flaw allows an attacker to access potentially sensitive information from the build system within the application.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-5720?
CVE-2023-5720 is a vulnerability that allows an attacker to access potentially sensitive information from the build system within the Quarkus application.
What is the severity of CVE-2023-5720?
CVE-2023-5720 has a severity rating of 7.7, which is considered high.
How does CVE-2023-5720 affect Quarkus?
CVE-2023-5720 affects Quarkus versions ranging from 3.0.0.CR1 to 3.5.1
How can I fix CVE-2023-5720?
To fix CVE-2023-5720, it is recommended to update Quarkus to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2023-5720?
More information about CVE-2023-5720 can be found at the following references: [Link 1](https://access.redhat.com/security/cve/CVE-2023-5720), [Link 2](https://bugzilla.redhat.com/show_bug.cgi?id=2245700), and [Link 3](https://nvd.nist.gov/vuln/detail/CVE-2023-5720).