RHSA-2022:4623MediumCVSS 8.0

Red Hat Security Advisory: Red Hat build of Quarkus 2.7.5 release and security update

Published
May 18, 2022
Last Modified
August 4, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2021-3914 — smallrye-health-ui: persistent cross-site scripting in endpoint CVE-2021-22569 — protobuf-java: potential DoS in the parsing procedure for binary data CVE-2021-29427 — gradle: repository content filters do not work in Settings pluginManagement CVE-2021-29428 — gradle: local privilege escalation through system temporary directory CVE-2021-29429 — gradle: information disclosure through temporary directory permissions CVE-2021-43797 — netty: control chars in header names may lead to HTTP request smuggling CVE-2022-0981 — quarkus: privilege escalation vulnerability with RestEasy Reactive scope leakage in Quarkus CVE-2022-21363 — mysql-connector-java: Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors CVE-2022-21724 — jdbc-postgresql: Unchecked Class Instantiation when providing Plugin Classes

🎯 Affected products1

  • Red Hat build of Quarkus 2.7.5

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link for the update. You must be logged in to download the update.

🔗 References (15)