RHSA-2024:1662HighCVSS 9.8

Red Hat Security Advisory: Red Hat build of Quarkus 3.2.11 release and security update

Published
April 3, 2024
Last Modified
August 4, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2024-1023 — io.vertx/vertx-core: memory leak due to the use of Netty FastThreadLocal data structures in Vertx CVE-2024-1300 — io.vertx:vertx-core: memory leak when a TCP server is configured with TLS and SNI support CVE-2024-1597 — pgjdbc: PostgreSQL JDBC Driver allows attacker to inject SQL if using PreferQueryMode=SIMPLE CVE-2024-1726 — quarkus: security checks for some inherited endpoints performed after serialization in RESTEasy Reactive may trigger a denial of service CVE-2024-1979 — quarkus: information leak in annotation CVE-2024-25710 — commons-compress: Denial of service caused by an infinite loop for a corrupted DUMP file CVE-2024-26308 — commons-compress: OutOfMemoryError unpacking broken Pack200 file

🎯 Affected products200

  • Red Hat build of Quarkus 3.2.11.Final
  • aopalliance.aopalliance-1.0.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • biz.aQute.bnd.biz.aQute.bnd.transform-6.3.1.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.aayushatharva.brotli4j.brotli4j-1.12.0.redhat-00005.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.aayushatharva.brotli4j.native-linux-x86_64-1.12.0.redhat-00005.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.aayushatharva.brotli4j.service-1.12.0.redhat-00005.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.apollographql.federation.federation-graphql-java-support-2.1.1.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.apollographql.federation.federation-graphql-java-support-api-2.1.1.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.cronutils.cron-utils-9.2.1.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.dajudge.kindcontainer.kindcontainer-1.3.0.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.fasterxml.classmate-1.5.1.redhat-00003.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.fasterxml.jackson.core.jackson-annotations-2.15.2.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.fasterxml.jackson.core.jackson-core-2.15.2.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.fasterxml.jackson.core.jackson-databind-2.15.2.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.fasterxml.jackson.dataformat.jackson-dataformat-properties-2.15.2.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.fasterxml.jackson.dataformat.jackson-dataformat-yaml-2.15.2.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.fasterxml.jackson.datatype.jackson-datatype-jdk8-2.15.2.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.fasterxml.jackson.datatype.jackson-datatype-jsr310-2.15.2.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.fasterxml.jackson.jakarta.rs.jackson-jakarta-rs-base-2.15.2.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.fasterxml.jackson.jakarta.rs.jackson-jakarta-rs-json-provider-2.15.2.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.fasterxml.jackson.module.jackson-module-jakarta-xmlbind-annotations-2.15.2.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.fasterxml.jackson.module.jackson-module-parameter-names-2.15.2.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.github.ben-manes.caffeine.caffeine-3.1.5.redhat-00001.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.github.docker-java.docker-java-api-3.3.0.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.github.docker-java.docker-java-transport-3.3.0.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.github.docker-java.docker-java-transport-zerodep-3.3.0.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.github.java-json-tools.btf-1.3.0.redhat-00003.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.github.java-json-tools.jackson-coreutils-2.0.0.redhat-00005.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.github.java-json-tools.json-patch-1.13.0.redhat-00007.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • com.github.java-json-tools.msg-simple-1.2.0.redhat-00002.jar as a component of Red Hat build of Quarkus 3.2.11.Final
  • +170 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Do not use the connection propertypreferQueryMode=simple. If you do not explicitly specify a query mode, then you are using the default of extended and are not impacted by this issue. Workaround: Ensure that at least one of the preconditions is not present in your environment. Workaround: No mitigation is currently available for this vulnerability.

🔗 References (18)