Red Hat Security Advisory: Red Hat build of Quarkus 2.7.5 release and security update
🔗 CVE IDs covered (9)
📋 Description
CVE-2021-3914 — smallrye-health-ui: persistent cross-site scripting in endpoint CVE-2021-22569 — protobuf-java: potential DoS in the parsing procedure for binary data CVE-2021-29427 — gradle: repository content filters do not work in Settings pluginManagement CVE-2021-29428 — gradle: local privilege escalation through system temporary directory CVE-2021-29429 — gradle: information disclosure through temporary directory permissions CVE-2021-43797 — netty: control chars in header names may lead to HTTP request smuggling CVE-2022-0981 — quarkus: privilege escalation vulnerability with RestEasy Reactive scope leakage in Quarkus CVE-2022-21363 — mysql-connector-java: Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors CVE-2022-21724 — jdbc-postgresql: Unchecked Class Instantiation when providing Plugin Classes
🎯 Affected products1
- Red Hat build of Quarkus 2.7.5
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link for the update. You must be logged in to download the update.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2022:4623
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=redhat.quarkus&downloadType=distributions&version=2.7.5
- externalhttps://access.redhat.com/documentation/en-us/red_hat_build_of_quarkus/2.7/
- externalhttps://access.redhat.com/articles/4966181
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1949636
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1949638
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1949643
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2018015
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2031958
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2039903
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2047343
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2050863
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2062520
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_4623.json