Cleartext storage of sensitive information in Quarkus - CVE-2024-2700

 

Cleartext storage of sensitive information in Quarkus - CVE-2024-2700

Published: June 11, 2024


Vulnerability identifier: #VU91686
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-2700
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to cleartext storage of sensitive information in an environment variable. A local user can exploit this vulnerability to obtain local configuration properties information, and use this information to launch further attacks against the affected system.


Affected software

Quarkus
Dell Data Protection Central
IBM Event Endpoint Management
Business Automation Insights
Red Hat OpenShift Serverless
AMQ Streams
Red Hat build of Quarkus
Red Hat Integration Camel Extensions for Quarkus
IBM Cloud Pak for Business Automation

How to mitigate CVE-2024-2700

Install updates from vendor's website.

Quarkus - addressed in versions 2.7.0, 3.2.12, 3.8.4
Dell Data Protection Central - update to 19.12.0-2
Red Hat OpenShift Serverless - update to 1.33.0
AMQ Streams - update to 2.7.0
Red Hat build of Quarkus - addressed in versions 3.2.12, 3.8.4
Red Hat Integration Camel Extensions for Quarkus - update to 3.2.12.GA
IBM Event Endpoint Management - update to 11.2.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF035, 21.0.3.33, 23.0.2.5, 24.0.0-IF001
Business Automation Insights - update to 23.0.2.0.5

External References

Related Security Bulletins