Red Hat Security Advisory: Red Hat build of Quarkus 2.13.5 release and security update
🔗 CVE IDs covered (8)
📋 Description
CVE-2022-3171 — protobuf-java: timeout in parser leads to DoS CVE-2022-4116 — quarkus_dev_ui: Dev UI Config Editor is vulnerable to drive-by localhost attacks leading to RCE CVE-2022-4147 — quarkus-vertx-http: Security misconfiguration of CORS : OWASP A05_2021 level in Quarkus CVE-2022-31197 — postgresql: SQL Injection in ResultSet.refreshRow() with malicious column names CVE-2022-37734 — graphql-java: DoS by malicious query CVE-2022-42003 — jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS CVE-2022-42004 — jackson-databind: use of deeply nested arrays CVE-2022-42889 — apache-commons-text: variable interpolation RCE
🎯 Affected products1
- Red Hat build of Quarkus 2.13.5
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: This flaw may be avoided by ensuring that any external inputs used with the Commons-Text lookup methods are sanitized properly. Untrusted input should always be thoroughly sanitized before using in any potentially risky situations.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2022:9023
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/articles/4966181
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=redhat.quarkus&version=2.13.5
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2126809
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2129428
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2135244
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2135247
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2135435
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2137645
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2144748
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2148867
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_9023.json