RHSA-2022:0589MediumCVSS 9.8

Red Hat Security Advisory: Red Hat build of Quarkus 2.2.5 release and security update

Published
February 21, 2022
Last Modified
July 16, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2021-2471 — mysql-connector-java: unauthorized access to critical CVE-2021-4178 — kubernetes-client: Insecure deserialization in unmarshalYaml method CVE-2021-28170 — jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate CVE-2021-37136 — netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data CVE-2021-37137 — netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary way CVE-2021-37714 — jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck CVE-2021-38153 — Kafka: Timing Attack Vulnerability for Apache Kafka Connect and Clients CVE-2021-41269 — cron-utils: template Injection leading to unauthenticated Remote Code Execution

🔗 References (14)