Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2024:6432 - Bug Fix Advisory
Issued:
2024-09-05
Updated:
2024-09-05

RHBA-2024:6432 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated RHEL-9 based Middleware Containers container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-9 based Middleware Containers container images are now available

Description

The RHEL-9 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2024:6163 (see References)

Users of RHEL-9 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The RHEL-9 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • Red Hat JBoss Middleware 1 x86_64

Fixes

  • BZ - 2302255 - CVE-2024-6923 cpython: python: email module doesn't properly quotes newlines in email headers, allowing header injection

CVEs

  • CVE-2024-6923
  • CVE-2024-37370
  • CVE-2024-37371

References

  • https://access.redhat.com/errata/RHSA-2024:6163
  • https://access.redhat.com/containers

aarch64

ubi9/openjdk-11@sha256:9e2e18226888910682e4c976c6a3a05083f16a2a06e1c06c4c9f56fce5aff43b
ubi9/openjdk-11-runtime@sha256:8ee34646eb13529edbda180b05229d4ea837124f17d9349d6452c0a963b35baf
ubi9/openjdk-17@sha256:9de143fac3531ee872baae9d5d08ca05d9b610b0a09a2c7d1c0f28c52782597f
ubi9/openjdk-17-runtime@sha256:c870e6b0d6218514b8bcf16767a4b80db40aeda28013e1e9a7bef9b82ec96852
ubi9/openjdk-21@sha256:5df3c00d7ee6d22b00bb4012b0800982c09e8ab0babfe1b8b6854fadd0bef3d3
ubi9/openjdk-21-runtime@sha256:f8ba8013976bfbd595b32f1bd74434e546398fb6ac15dd4154ddfe3fc64d5265

ppc64le

ubi9/openjdk-11@sha256:2962ea02e03cf9c92a967888d2934fbb9148815b40c9243a625fd8addf941952
ubi9/openjdk-11-runtime@sha256:2b8c263f928e837d1564244ef700b02743c7b8711e6683ec69d1efb66c013c52
ubi9/openjdk-17@sha256:21aecea7379151cbacf74ebdd73a7b71b804f4ef088103577a4c9b31eef49e4c
ubi9/openjdk-17-runtime@sha256:36dd4ee1dcc3718a2fafe161d4e0ce9699c3b3551d5442757a624084ee9389bf
ubi9/openjdk-21@sha256:bd153a63000ab9c9d5134b62b51eb6277f797255c2448f7e7235ba5df82a9da6
ubi9/openjdk-21-runtime@sha256:431b919405f3dd25b1c0e913d5f936e59384da84c5673c3590cf27e88513c8fb

s390x

ubi9/openjdk-11@sha256:9cf9a77d07e9856d16f893bd85b72c1eb0df31f547571987ee60684265ab9b79
ubi9/openjdk-11-runtime@sha256:0ea36d69397a951f4d2ab7d23610d7bebfea06aa5e5b9e9c928e9314d00af0ed
ubi9/openjdk-17@sha256:90d5f244422a02d3d3b10327e9806fbb81cc2d50b8149e3c5ae98cb8dfd18221
ubi9/openjdk-17-runtime@sha256:f884a0b17ff5aa6a7246d4e7cfdd243476e7d17dc5fc1be4766dd78edf1c3b7c
ubi9/openjdk-21@sha256:835723d92be7d7d607e146ab4c1f12ab010fa15c957f92e21bece6a188a45627
ubi9/openjdk-21-runtime@sha256:7425fe2dbc9cf6e280864c6ca82eaf0c3415b3d11b335ce28eebf4e59b712a46

x86_64

ubi9/openjdk-11@sha256:41a67c8b46080538bea33025c594ec7afa13b685c2fb4a7c15bb34b59c0ce3ed
ubi9/openjdk-11-runtime@sha256:09c819a0d983e6d8cd1ce70d9b65a6060d12737d6a52b227fab9dd4ce405c274
ubi9/openjdk-17@sha256:4f698eca52005b34464f40829625e6f1f3f559f8bade30d2a1df39df23092f8e
ubi9/openjdk-17-runtime@sha256:34c0d920d3deb8430f4c8d8fc4be9746c176f36d8b77f7fa2c4edce36f11cb10
ubi9/openjdk-21@sha256:aaecb66d5a194b2c4b8452969dae64de4ba4238a8a1f08b7dfc1e7608d7a1295
ubi9/openjdk-21-runtime@sha256:d48663169e5461c21380ed2826656c5bcac81a630b9e69aeb3e57077b67e2a76

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility