RHSA-2024:7670CriticalCVSS 8.8
Red Hat Security Advisory: Red Hat build of Quarkus 3.8.6.SP1 Security Update
🔗 CVE IDs covered (4)
📋 Description
CVE-2021-44549 — angus-mail: Enabling Secure Server Identity Checks for Safer SMTPS Communication CVE-2024-7254 — protobuf: StackOverflow vulnerability in Protocol Buffers CVE-2024-40094 — graphql-java: Allocation of Resources Without Limits or Throttling in GraphQL Java CVE-2024-47561 — apache-avro: Schema parsing may trigger Remote Code Execution (RCE)
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2024:7670
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://docs.redhat.com/en/documentation/red_hat_build_of_quarkus/3.8
- externalhttps://access.redhat.com/articles/4966181
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_7670.json