Description
A vulnerability was found in Quarkus. In certain conditions related to the CI process, git credentials could be inadvertently published, which could put the git repository at risk.
Problem types
Exposure of Sensitive Information to an Unauthorized Actor
Product status
Any version before 3.2.11
3.2.11.Final-redhat-00001 (rpm) before *
Timeline
2024-03-04: | Reported to Red Hat. |
2024-01-05: | Made public. |
References
access.redhat.com/errata/RHSA-2024:1662 (RHSA-2024:1662)
access.redhat.com/security/cve/CVE-2024-1979
bugzilla.redhat.com/show_bug.cgi?id=2266690 (RHBZ#2266690)
github.com/quarkusio/quarkus/issues/38055