First published: Mon Feb 21 2022(Updated: )
This release of Red Hat build of Quarkus 2.2.5 includes security updates, bug fixes, and enhancements. For more information, see the release notes page listed in the References section.<br>Security Fix(es):<br><li> kafka-clients: Kafka: Timing Attack Vulnerability for Apache Kafka Connect and Clients (CVE-2021-38153)</li> <li> kubernetes-client: Insecure deserialization in unmarshalYaml method (CVE-2021-4178)</li> <li> jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck (CVE-2021-37714)</li> <li> jakarta.el: jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate (CVE-2021-28170)</li> <li> netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data (CVE-2021-37136)</li> <li> netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary way (CVE-2021-37137)</li> <li> mysql-connector-java: unauthorized access to critical (CVE-2021-2471)</li> <li> cron-utils: template Injection leading to unauthenticated Remote Code Execution(CVE-2021-41269)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.