RHSA-2024:1797HighCVSS 9.8

Red Hat Security Advisory: Red Hat build of Quarkus 2.13.9.SP2 release and security update

Published
April 22, 2024
Last Modified
August 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2024-1597 — pgjdbc: PostgreSQL JDBC Driver allows attacker to inject SQL if using PreferQueryMode=SIMPLE CVE-2024-25710 — commons-compress: Denial of service caused by an infinite loop for a corrupted DUMP file CVE-2024-26308 — commons-compress: OutOfMemoryError unpacking broken Pack200 file

🎯 Affected products200

  • Red Hat build of Quarkus 2.13.9.SP2
  • antlr.antlr-2.7.7.redhat-7.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • aopalliance.aopalliance-1.0.0.redhat-00003.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • biz.aQute.bnd.biz.aQute.bnd.transform-6.3.1.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.aayushatharva.brotli4j.brotli4j-1.12.0.redhat-00005.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.aayushatharva.brotli4j.native-linux-x86_64-1.12.0.redhat-00005.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.aayushatharva.brotli4j.service-1.12.0.redhat-00005.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.carrotsearch.hppc-0.8.1.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.cronutils.cron-utils-9.2.0.redhat-00001.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.fasterxml.classmate-1.5.1.redhat-00003.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.fasterxml.jackson.core.jackson-annotations-2.13.4.redhat-00004.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.fasterxml.jackson.core.jackson-core-2.13.4.redhat-00004.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.fasterxml.jackson.core.jackson-databind-2.13.4.2-redhat-00001.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.fasterxml.jackson.dataformat.jackson-dataformat-properties-2.13.4.redhat-00004.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.fasterxml.jackson.dataformat.jackson-dataformat-yaml-2.13.4.redhat-00004.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.fasterxml.jackson.datatype.jackson-datatype-jdk8-2.13.4.redhat-00004.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.fasterxml.jackson.datatype.jackson-datatype-jsr310-2.13.4.redhat-00004.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.fasterxml.jackson.jaxrs.jackson-jaxrs-base-2.13.4.redhat-00004.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.fasterxml.jackson.jaxrs.jackson-jaxrs-json-provider-2.13.4.redhat-00004.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.fasterxml.jackson.module.jackson-module-jaxb-annotations-2.13.4.redhat-00004.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.fasterxml.jackson.module.jackson-module-parameter-names-2.13.4.redhat-00004.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.github.ben-manes.caffeine.caffeine-2.9.3.redhat-00003.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.github.docker-java.docker-java-api-3.2.13.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.github.docker-java.docker-java-transport-3.2.13.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.github.docker-java.docker-java-transport-zerodep-3.2.13.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.github.java-json-tools.btf-1.3.0.redhat-00003.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.github.java-json-tools.jackson-coreutils-2.0.0.redhat-00005.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.github.java-json-tools.json-patch-1.13.0.redhat-00007.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.github.java-json-tools.msg-simple-1.2.0.redhat-00002.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • com.github.javaparser.javaparser-core-3.24.2.redhat-00003.jar as a component of Red Hat build of Quarkus 2.13.9.SP2
  • +170 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Do not use the connection propertypreferQueryMode=simple. If you do not explicitly specify a query mode, then you are using the default of extended and are not impacted by this issue. Workaround: No mitigation is currently available for this vulnerability.

🔗 References (8)