LOW3.5
GHSA-7g97-7r3c-5cc6
In Quarkus, git credentials could be inadvertently published
Quick fix
GHSA-7g97-7r3c-5cc6 — io.quarkus:quarkus-kubernetes-deployment: upgrade to the fixed version with the command below.
# pom.xml: bump <version>3.7.3</version> for io.quarkus:quarkus-kubernetes-deploymentDetails
A vulnerability was found in Quarkus. In certain conditions related to the CI process, git credentials could be inadvertently published, which could put the git repository at risk.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/io.quarkus:quarkus-kubernetes-deployment
Introduced in:
0Fixed in: 3.7.3Fix
# pom.xml: bump <version>3.7.3</version> for io.quarkus:quarkus-kubernetes-deploymentReferences
- https://nvd.nist.gov/vuln/detail/CVE-2024-1979[ADVISORY]
- https://github.com/quarkusio/quarkus/issues/38055[WEB]
- https://github.com/quarkusio/quarkus/commit/3a3b0d739222a2e476e085a955cfa090739f5924[WEB]
- https://github.com/quarkusio/quarkus/commit/5bc05ee35365a905f0e9e37f248c38688a81caaf[WEB]
- https://access.redhat.com/errata/RHSA-2024:1662[WEB]
- https://access.redhat.com/security/cve/CVE-2024-1979[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2266690[WEB]
- https://github.com/quarkusio/quarkus[PACKAGE]