Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2024-2700
Java vulnerability analysis and mitigation

Overview

A vulnerability (CVE-2024-2700) was discovered in the quarkus-core component affecting Quarkus applications. The vulnerability was disclosed on April 4, 2024, and involves the capture of local environment variables from the Quarkus namespace during application build time. This issue affects various Red Hat products including Red Hat build of Quarkus, Red Hat AMQ Streams, Red Hat OpenShift Serverless, and Red Hat build of Apicurio Registry (Red Hat CVE).

Technical details

The vulnerability occurs when Quarkus captures local environment variables from the Quarkus namespace during the application's build process. The resulting application inherits these values at build time. This behavior specifically affects configuration properties from the quarkus.* namespace, while application-specific properties are not captured. The vulnerability has been assigned a CVSS v3.1 base score of 7.0 (HIGH) with the vector string CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H (NVD Database).

Impact

If exploited, this vulnerability can lead to dangerous behavior when environment variables or .env facility configurations set during development or CI testing (such as database dropping commands or TLS certificate trust settings) are captured into the built application. These captured configurations persist in the production environment if not explicitly overridden, potentially leading to security risks (Red Hat Bugzilla).

Exploitability

The vulnerability requires local access and high complexity to exploit. It affects scenarios where environment variables are set during development or CI/CD processes, particularly those involving sensitive configurations like database operations or TLS certificate handling (Red Hat Advisory).

Mitigation and workarounds

Multiple security updates have been released to address this vulnerability across different Red Hat products. These include Red Hat build of Quarkus 3.8.4 (RHSA-2024:2106), Quarkus 3.2.12 (RHSA-2024:2705), AMQ Streams 2.7.0 (RHSA-2024:3527), OpenShift Serverless 1.33.0 (RHSA-2024:4028), and Apicurio Registry 2.6.1 GA (RHSA-2024:4873). Users are advised to update to these patched versions (Red Hat Security).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-53837CRITICAL9.9
  • Java logoJava
  • org.xwiki.rendering:xwiki-rendering-xml
NoYesSep 18, 2026
CVE-2026-77615HIGH8.7
  • JavaScript logoJavaScript
  • paella-core
NoYesSep 17, 2026
CVE-2026-54148HIGH8.1
  • Java logoJava
  • org.http4k:http4k-security-digest
NoYesSep 18, 2026
CVE-2026-85058HIGH7.5
  • Java logoJava
  • io.moquette:moquette-broker
NoYesSep 18, 2026
CVE-2026-54147MEDIUM6.5
  • Java logoJava
  • org.http4k:http4k-security-digest
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management