Red Hat Security Advisory: Red Hat build of Quarkus 1.11.6 release and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2020-25633 — resteasy-client: potential sensitive information leakage in JAX-RS RESTEasy Client's WebApplicationException handling CVE-2020-25724 — resteasy: information disclosure via HTTP response reuse CVE-2020-26238 — cron-utils: template injection allows attackers to inject arbitrary Java EL expressions leading to remote code execution CVE-2021-20218 — fabric8-kubernetes-client: vulnerable to a path traversal leading to integrity and availability compromise
🎯 Affected products1
- Text-Only RHOAR
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link for the update. You must be logged in to download the update.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2021:1004
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=redhat.quarkus&downloadType=distributions&version=1.11.6
- externalhttps://access.redhat.com/documentation/en-us/red_hat_build_of_quarkus/1.11/
- externalhttps://access.redhat.com/articles/4966181
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1879042
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1899354
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1901655
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1923405
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_1004.json