RHSA-2024:0722HighCVSS 7.5
Red Hat Security Advisory: Red Hat build of Quarkus 3.2.10 release and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-4043 — parsson: Denial of Service due to large number parsing
🎯 Affected products200
- Red Hat build of Quarkus 3.2.10.Final
- aopalliance.aopalliance-1.0.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- biz.aQute.bnd.biz.aQute.bnd.transform-6.3.1.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.aayushatharva.brotli4j.brotli4j-1.12.0.redhat-00005.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.aayushatharva.brotli4j.native-linux-x86_64-1.12.0.redhat-00005.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.aayushatharva.brotli4j.service-1.12.0.redhat-00005.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.apollographql.federation.federation-graphql-java-support-2.1.1.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.apollographql.federation.federation-graphql-java-support-api-2.1.1.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.cronutils.cron-utils-9.2.1.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.dajudge.kindcontainer.kindcontainer-1.3.0.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.fasterxml.classmate-1.5.1.redhat-00003.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.fasterxml.jackson.core.jackson-annotations-2.15.2.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.fasterxml.jackson.core.jackson-core-2.15.2.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.fasterxml.jackson.core.jackson-databind-2.15.2.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.fasterxml.jackson.dataformat.jackson-dataformat-properties-2.15.2.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.fasterxml.jackson.dataformat.jackson-dataformat-yaml-2.15.2.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.fasterxml.jackson.datatype.jackson-datatype-jdk8-2.15.2.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.fasterxml.jackson.datatype.jackson-datatype-jsr310-2.15.2.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.fasterxml.jackson.jakarta.rs.jackson-jakarta-rs-base-2.15.2.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.fasterxml.jackson.jakarta.rs.jackson-jakarta-rs-json-provider-2.15.2.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.fasterxml.jackson.module.jackson-module-jakarta-xmlbind-annotations-2.15.2.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.fasterxml.jackson.module.jackson-module-parameter-names-2.15.2.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.github.ben-manes.caffeine.caffeine-3.1.5.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.github.docker-java.docker-java-api-3.3.0.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.github.docker-java.docker-java-transport-3.3.0.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.github.docker-java.docker-java-transport-zerodep-3.3.0.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.github.java-json-tools.btf-1.3.0.redhat-00003.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.github.java-json-tools.jackson-coreutils-2.0.0.redhat-00005.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.github.java-json-tools.json-patch-1.13.0.redhat-00007.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- com.github.java-json-tools.msg-simple-1.2.0.redhat-00002.jar as a component of Red Hat build of Quarkus 3.2.10.Final
- +170 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Avoid processing untrusted sources content in order to minimize the chance for Denial of Service attack.
🔗 References (36)
- selfhttps://access.redhat.com/errata/RHSA-2024:0722
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en-us/red_hat_build_of_quarkus/3.2/
- externalhttps://access.redhat.com/articles/4966181
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254210
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254594
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2256474
- externalhttps://issues.redhat.com/browse/QUARKUS-3791
- externalhttps://issues.redhat.com/browse/QUARKUS-3851
- externalhttps://issues.redhat.com/browse/QUARKUS-3938
- externalhttps://issues.redhat.com/browse/QUARKUS-3939
- externalhttps://issues.redhat.com/browse/QUARKUS-3940
- externalhttps://issues.redhat.com/browse/QUARKUS-3941
- externalhttps://issues.redhat.com/browse/QUARKUS-3942
- externalhttps://issues.redhat.com/browse/QUARKUS-3943
- externalhttps://issues.redhat.com/browse/QUARKUS-3944
- externalhttps://issues.redhat.com/browse/QUARKUS-3945
- externalhttps://issues.redhat.com/browse/QUARKUS-3946
- externalhttps://issues.redhat.com/browse/QUARKUS-3947
- externalhttps://issues.redhat.com/browse/QUARKUS-3948
- externalhttps://issues.redhat.com/browse/QUARKUS-3949
- externalhttps://issues.redhat.com/browse/QUARKUS-3950
- externalhttps://issues.redhat.com/browse/QUARKUS-3951
- externalhttps://issues.redhat.com/browse/QUARKUS-3952
- externalhttps://issues.redhat.com/browse/QUARKUS-3953
- externalhttps://issues.redhat.com/browse/QUARKUS-3954
- externalhttps://issues.redhat.com/browse/QUARKUS-3955
- externalhttps://issues.redhat.com/browse/QUARKUS-3956
- externalhttps://issues.redhat.com/browse/QUARKUS-3957
- externalhttps://issues.redhat.com/browse/QUARKUS-3958
- externalhttps://issues.redhat.com/browse/QUARKUS-3959
- externalhttps://issues.redhat.com/browse/QUARKUS-3960
- externalhttps://issues.redhat.com/browse/QUARKUS-3961
- externalhttps://issues.redhat.com/browse/QUARKUS-3963
- externalhttps://issues.redhat.com/browse/QUARKUS-3964
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0722.json