First published: Tue Dec 13 2022(Updated: )
This release of Red Hat build of Quarkus 2.7.6.SP3 includes security updates, bug fixes, and enhancements. For more information, see the release notes page listed in the References section.<br>Security Fix(es):<br><li> CVE-2022-4147 quarkus-vertx-<a href="http:" target="_blank">http:</a> Security misconfiguration of CORS : OWASP A05_2021 level in Quarkus</li> <li> CVE-2022-4116 quarkus_dev_ui: Dev UI Config Editor is vulnerable to drive-by localhost attacks leading to RCE</li> <li> CVE-2022-45047 mina-sshd: Java unsafe deserialization vulnerability</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s)<br>listed in the References section.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.