Red Hat Security Advisory: Red Hat build of Quarkus 2.2.3 release and security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2020-28491 — jackson-dataformat-cbor: Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception CVE-2021-3642 — wildfly-elytron: possible timing attack in ScramServer CVE-2021-20289 — resteasy: Error message exposes endpoint class information CVE-2021-21290 — netty: Information disclosure via the local system temporary directory CVE-2021-21295 — netty: possible request smuggling in HTTP/2 due missing validation CVE-2021-21409 — netty: Request smuggling via content-length header CVE-2021-26291 — maven: Block repositories using http by default
🎯 Affected products1
- Red Hat build of Quarkus 2.2.3
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link for the update. You must be logged in to download the update. Workaround: To avoid possible man-in-the-middle related attacks with this flaw, ensure any linked repositories in maven POMs use https and not http.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2021:3880
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=redhat.quarkus&downloadType=distributions&version=2.2.3
- externalhttps://access.redhat.com/documentation/en-us/red_hat_build_of_quarkus/2.2/
- externalhttps://access.redhat.com/articles/4966181
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1927028
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1930423
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1935927
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1937364
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1944888
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1955739
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1981407
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_3880.json