
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability (CVE-2024-2700) was discovered in the quarkus-core component affecting Quarkus applications. The vulnerability was disclosed on April 4, 2024, and involves the capture of local environment variables from the Quarkus namespace during application build time. This issue affects various Red Hat products including Red Hat build of Quarkus, Red Hat AMQ Streams, Red Hat OpenShift Serverless, and Red Hat build of Apicurio Registry (Red Hat CVE).
The vulnerability occurs when Quarkus captures local environment variables from the Quarkus namespace during the application's build process. The resulting application inherits these values at build time. This behavior specifically affects configuration properties from the quarkus.* namespace, while application-specific properties are not captured. The vulnerability has been assigned a CVSS v3.1 base score of 7.0 (HIGH) with the vector string CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H (NVD Database).
If exploited, this vulnerability can lead to dangerous behavior when environment variables or .env facility configurations set during development or CI testing (such as database dropping commands or TLS certificate trust settings) are captured into the built application. These captured configurations persist in the production environment if not explicitly overridden, potentially leading to security risks (Red Hat Bugzilla).
The vulnerability requires local access and high complexity to exploit. It affects scenarios where environment variables are set during development or CI/CD processes, particularly those involving sensitive configurations like database operations or TLS certificate handling (Red Hat Advisory).
Multiple security updates have been released to address this vulnerability across different Red Hat products. These include Red Hat build of Quarkus 3.8.4 (RHSA-2024:2106), Quarkus 3.2.12 (RHSA-2024:2705), AMQ Streams 2.7.0 (RHSA-2024:3527), OpenShift Serverless 1.33.0 (RHSA-2024:4028), and Apicurio Registry 2.6.1 GA (RHSA-2024:4873). Users are advised to update to these patched versions (Red Hat Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."