Description
A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing certain build system information to remain. This flaw allows an attacker to access potentially sensitive information from the build system within the application.
Remediation
References
https://access.redhat.com/security/cve/CVE-2023-5720
https://bugzilla.redhat.com/show_bug.cgi?id=2245700
Related Vulnerabilities
CVE-2022-46687 Vulnerability in maven package io.jenkins.plugins:spring-config
CVE-2017-9805 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2017-15681 Vulnerability in maven package org.craftercms:crafter-studio
CVE-2020-8897 Vulnerability in maven package com.amazonaws:aws-encryption-sdk-java
CVE-2021-41561 Vulnerability in maven package org.apache.parquet:parquet