- Issued:
- 2024-05-07
- Updated:
- 2024-05-07
RHSA-2024:2106 - Security Advisory
Synopsis
Moderate: Red Hat build of Quarkus 3.8.4 release
Type/Severity
Security Advisory: Moderate
Topic
An update is now available for Red Hat build of Quarkus.
Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. For more information, see the CVE links in the References section.
Description
This release of Red Hat build of Quarkus 3.8.4 includes security updates. For more information, see the release notes page listed in the References section.
Security Fix(es):
- CVE-2024-2700 io.quarkus/quarkus-core: Leak of local configuration properties into Quarkus applications [quarkus-3.8]
- TRIAGE CVE-2024-29025 io.netty/netty-codec-http: Allocation of Resources Without Limits or Throttling [quarkus-3.8]
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
Affected Products
- Red Hat build of Quarkus Text-Only Advisories x86_64
Fixes
- BZ - 2272907 - CVE-2024-29025 netty-codec-http: Allocation of Resources Without Limits or Throttling
- BZ - 2273281 - CVE-2024-2700 quarkus-core: Leak of local configuration properties into Quarkus applications
- QUARKUS-4289 - [3.8] Prevent smallrye-graphql-schema-builder from leaking into runtime deps
- QUARKUS-4291 - Fix datasource devservices restarting
- QUARKUS-4293 - Update - Only consider recipes when generating the list of recipes
- QUARKUS-4294 - Bump the `recommended-java-version` to 21
- QUARKUS-4295 - Add js-scriptengine and collections as parent first artifacts
- QUARKUS-4296 - No build time init of classes used in `UnsafeAccessedFieldBuildItem`
- QUARKUS-4297 - Fix native compilation for Netty and Mutiny
- QUARKUS-4298 - Bump JDK version to 17 as an aws lambda runtime in aws-lambda related extensions
- QUARKUS-4301 - Update Hibernate ORM package/class processing rules
- QUARKUS-4302 - Use --no-daemon when calling gradle update
- QUARKUS-4303 - Bring back erroneously removed @BuildStep
- QUARKUS-4306 - Properly use headers from RestMulti when the multi is empty
- QUARKUS-4308 - Fix Quarkus REST Jackson @SecureField detection on subclasses, interface implementors, fileds of the fields, parametrized types and arrays
- QUARKUS-4313 - Remove the old MetricBuildItem SPI
- QUARKUS-4314 - Fix codestarts compatibility with older CLI
- QUARKUS-4315 - Handle null Vert.x context in smallrye-health
- QUARKUS-4316 - Isolate Avro schema code generation when using multiple schema files
- QUARKUS-4317 - Add missing headers configuration for InputStream handling
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.