RHSA-2020:4252HighCVSS 7.5

Red Hat Security Advisory: Red Hat build of Quarkus 1.7.5 release and security update

Published
October 14, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2019-14900 — hibernate: SQL injection issue in Hibernate ORM CVE-2020-1714 — keycloak: Lack of checks in ObjectInputStream leading to Remote Code Execution CVE-2020-1728 — keycloak: security headers missing on REST endpoints CVE-2020-10693 — hibernate-validator: Improper input validation in the interpolation of constraint error messages CVE-2020-11612 — netty: compression/decompression codecs don't enforce limits on buffer allocation sizes

🎯 Affected products1

  • Red Hat build of Quarkus 1.7.5

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link for the update. You must be logged in to download the update. Workaround: There is no currently known mitigation for this flaw. Workaround: There is currently no known mitigation for this issue. Workaround: You can pass user input as an expression variable by unwrapping the context to HibernateConstraintValidatorContext. Please refer to the https://in.relation.to/2020/05/07/hibernate-validator-615-6020-released/ and https://docs.jboss.org/hibernate/stable/validator/reference/en-US/html_single/#_the_code_constraintvalidatorcontext_code.

🔗 References (11)