Risk Scores
CVSS v3.1
3.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
EPSS Score
0.07%
21.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Maven | io.quarkus:quarkus-kubernetes-deployment | 0, 0, 0 |
| Red Hat | Red Hat build of Quarkus 3.2.11.Final | 3.2.11.Final-redhat-00001, 3.2.11.Final-redhat-00001, 3.2.11.Final-redhat-00001 |
| Red Hat | Red Hat build of Quarkus | |
| 0, 0, 0 |
Timeline
- Mar 13, 2024 CVE Published
- Mar 13, 2024 PoC Published
- Mar 13, 2024 PoC Published
- Mar 14, 2024 EPSS Score
- Apr 8, 2024 EPSS Score
- May 4, 2024 EPSS Score
- May 29, 2024 EPSS Score
- Jun 24, 2024 EPSS Score
- Jul 19, 2024 EPSS Score
- Aug 17, 2024 EPSS Score
- Sep 12, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
References
- RHSA-2024:1662 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-1979 vdb
- RHBZ#2266690 issue
- https://github.com/quarkusio/quarkus/issues/38055 url
- https://nvd.nist.gov/vuln/detail/CVE-2024-1979 advisory
- https://github.com/quarkusio/quarkus/commit/3a3b0d739222a2e476e085a955cfa090739f5924 url
- https://github.com/quarkusio/quarkus/commit/5bc05ee35365a905f0e9e37f248c38688a81caaf url
- https://github.com/quarkusio/quarkus package