RHSA-2024:9571MediumCVSS 7.5
Red Hat Security Advisory: Streams for Apache Kafka 2.8.0 release and security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2024-7254 — protobuf: StackOverflow vulnerability in Protocol Buffers CVE-2024-8184 — org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks CVE-2024-8285 — kroxylicious: Missing upstream Kafka TLS hostname verification CVE-2024-9823 — org.eclipse.jetty:jetty-servlets: jetty: Jetty DOS vulnerability on DosFilter CVE-2024-29025 — netty-codec-http: Allocation of Resources Without Limits or Throttling CVE-2024-47554 — apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReader
🔗 References (33)
- selfhttps://access.redhat.com/errata/RHSA-2024:9571
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2272907
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2308606
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2313454
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2316271
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2318564
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2318565
- externalhttps://issues.redhat.com/browse/ASUI-91
- externalhttps://issues.redhat.com/browse/ENTMQST-2632
- externalhttps://issues.redhat.com/browse/ENTMQST-3288
- externalhttps://issues.redhat.com/browse/ENTMQST-4019
- externalhttps://issues.redhat.com/browse/ENTMQST-5199
- externalhttps://issues.redhat.com/browse/ENTMQST-5669
- externalhttps://issues.redhat.com/browse/ENTMQST-5674
- externalhttps://issues.redhat.com/browse/ENTMQST-5740
- externalhttps://issues.redhat.com/browse/ENTMQST-5789
- externalhttps://issues.redhat.com/browse/ENTMQST-5843
- externalhttps://issues.redhat.com/browse/ENTMQST-5850
- externalhttps://issues.redhat.com/browse/ENTMQST-5863
- externalhttps://issues.redhat.com/browse/ENTMQST-5865
- externalhttps://issues.redhat.com/browse/ENTMQST-5915
- externalhttps://issues.redhat.com/browse/ENTMQST-6028
- externalhttps://issues.redhat.com/browse/ENTMQST-6032
- externalhttps://issues.redhat.com/browse/ENTMQST-6129
- externalhttps://issues.redhat.com/browse/ENTMQST-6183
- externalhttps://issues.redhat.com/browse/ENTMQST-6205
- externalhttps://issues.redhat.com/browse/ENTMQST-6225
- externalhttps://issues.redhat.com/browse/ENTMQST-6341
- externalhttps://issues.redhat.com/browse/ENTMQST-6421
- externalhttps://issues.redhat.com/browse/ENTMQST-6422
- externalhttps://issues.redhat.com/browse/ENTMQSTPR-43
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_9571.json