Red Hat Security Advisory: Red Hat build of Quarkus 2.13.9 release and security update
🔗 CVE IDs covered (11)
📋 Description
CVE-2023-2976 — guava: insecure temporary directory creation CVE-2023-6393 — quarkus: Potential invalid reuse of context when @CacheResult on a Uni is used CVE-2023-6394 — quarkus: GraphQL operations over WebSockets bypass CVE-2023-31582 — jose4j: Insecure iteration count setting CVE-2023-34453 — snappy-java: Integer overflow in shuffle leads to DoS CVE-2023-34454 — snappy-java: Integer overflow in compress leads to DoS CVE-2023-34455 — snappy-java: Unchecked chunk length leads to DoS CVE-2023-34462 — netty: SniHandler 16MB allocation leads to OOM CVE-2023-35887 — apache-mina-sshd: information exposure in SFTP server implementations CVE-2023-39410 — apache-avro: Apache Avro Java SDK: Memory when deserializing untrusted data in Avro Java SDK CVE-2023-43642 — snappy-java: Missing upper bound check on chunk length in snappy-java can lead to Denial of Service (DoS) impact
🎯 Affected products200
- Red Hat build of Quarkus 2.13.9.Final
- antlr.antlr-2.7.7.redhat-7.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- aopalliance.aopalliance-1.0.0.redhat-00003.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- biz.aQute.bnd.biz.aQute.bnd.transform-6.3.1.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.aayushatharva.brotli4j.brotli4j-1.12.0.redhat-00005.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.aayushatharva.brotli4j.native-linux-x86_64-1.12.0.redhat-00005.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.aayushatharva.brotli4j.service-1.12.0.redhat-00005.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.carrotsearch.hppc-0.8.1.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.cronutils.cron-utils-9.2.0.redhat-00001.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.fasterxml.classmate-1.5.1.redhat-00003.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.fasterxml.jackson.core.jackson-annotations-2.13.4.redhat-00004.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.fasterxml.jackson.core.jackson-core-2.13.4.redhat-00004.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.fasterxml.jackson.core.jackson-databind-2.13.4.2-redhat-00001.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.fasterxml.jackson.dataformat.jackson-dataformat-properties-2.13.4.redhat-00004.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.fasterxml.jackson.dataformat.jackson-dataformat-yaml-2.13.4.redhat-00004.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.fasterxml.jackson.datatype.jackson-datatype-jdk8-2.13.4.redhat-00004.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.fasterxml.jackson.datatype.jackson-datatype-jsr310-2.13.4.redhat-00004.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.fasterxml.jackson.jaxrs.jackson-jaxrs-base-2.13.4.redhat-00004.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.fasterxml.jackson.jaxrs.jackson-jaxrs-json-provider-2.13.4.redhat-00004.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.fasterxml.jackson.module.jackson-module-jaxb-annotations-2.13.4.redhat-00004.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.fasterxml.jackson.module.jackson-module-parameter-names-2.13.4.redhat-00004.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.github.ben-manes.caffeine.caffeine-2.9.3.redhat-00003.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.github.docker-java.docker-java-api-3.2.13.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.github.docker-java.docker-java-transport-3.2.13.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.github.docker-java.docker-java-transport-zerodep-3.2.13.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.github.java-json-tools.btf-1.3.0.redhat-00003.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.github.java-json-tools.jackson-coreutils-2.0.0.redhat-00005.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.github.java-json-tools.json-patch-1.13.0.redhat-00007.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.github.java-json-tools.msg-simple-1.2.0.redhat-00002.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- com.github.javaparser.javaparser-core-3.24.2.redhat-00003.jar as a component of Red Hat build of Quarkus 2.13.9.Final
- +170 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Temp files should be created with sufficiently non-predictable names and in a secure-permissioned, dedicated temp folder. Workaround: No mitigation is currently available for this flaw. Workaround: Configuration of SniHandler with an idle timeout will mitigate this issue.
🔗 References (19)
- selfhttps://access.redhat.com/errata/RHSA-2023:7700
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en-us/red_hat_build_of_quarkus/2.13/
- externalhttps://access.redhat.com/articles/4966181
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2215229
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2215393
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2215394
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2215445
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2216888
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2240036
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2241722
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2242521
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2246370
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2253113
- externalhttps://issues.redhat.com/browse/QUARKUS-3781
- externalhttps://issues.redhat.com/browse/QUARKUS-3782
- externalhttps://issues.redhat.com/browse/QUARKUS-3785
- externalhttps://issues.redhat.com/browse/QUARKUS-3787
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_7700.json