CVE-2023-5720 Vulnerability Details

  /     /     /  

CVE-2023-5720 Metadata Quick Info

CVE Published: 15/11/2023 | CVE Updated: 02/08/2024 | CVE Year: 2023
Source: redhat | Vendor: n/a | Product: gradle-plugin
Status : PUBLISHED

CVE-2023-5720 Description

A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing certain build system information to remain. This flaw allows an attacker to access potentially sensitive information from the build system within the application.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-526
CWE Name: Cleartext Storage of Sensitive Information in an Environment Variable
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).