REDHAT-BUG-2374376: Medium severity Red Hat Quarkus vulnerability

Published Jun 23, 2025
·
Updated

Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. In versions prior to 3.24.0, there is a potential data leak when duplicating a duplicated context. Quarkus extensively uses the Vert.x duplicated context to implement context propagation. With the new semantic data from one transaction can leak to the data from another transaction. From a Vert.x point of view, this new semantic clarifies the behavior. A significant amount of data is stored in the duplicated context, including request scope, security details, and metadata. Duplicating a duplicated context is rather rare and is only done in a few places. This issue has been patched in version 3.24.0.

Affected Software

1 affected component
Red Hat Quarkus<3.24.0

Event History

Jun 23, 2025
Data Sourced
via Red Hat·08:01 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2374376?

The severity of REDHAT-BUG-2374376 is considered significant due to the potential data leak it presents.

2

How do I fix REDHAT-BUG-2374376?

To fix REDHAT-BUG-2374376, upgrade to Quarkus version 3.24.0 or later.

3

Who is affected by REDHAT-BUG-2374376?

Developers using Red Hat Quarkus versions prior to 3.24.0 are affected by REDHAT-BUG-2374376.

4

What is the nature of the issue in REDHAT-BUG-2374376?

REDHAT-BUG-2374376 involves a potential data leak caused by duplicating a duplicated context in Quarkus.

5

Is there a workaround for REDHAT-BUG-2374376?

There is no official workaround for REDHAT-BUG-2374376, so the recommended action is to update to the fixed version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203