RHSA-2024:0494: Important: Red Hat build of Quarkus 2.13.9.SP1 release and security update
Important: Red Hat build of Quarkus 2.13.9.SP1 release and security update
Other sources
This release of Red Hat build of Quarkus 2.13.9.SP1 includes security updates, bug fixes, and enhancements. For more information, see the release notes page listed in the References section.EMBARGOED TRIAGE CVE-2023-6267 : io.quarkus.resteasy.reactive/resteasy-reactive: quarkus: json payload getting processed prior to security checks when rest resources are used with annotations. [quarkus-2]EMBARGOED CVE-2023-5675 : io.quarkus.resteasy.reactive/resteasy-reactive: quarkus: Authorization flaw in Quarkus RestEasy Reactive and Classic when "quarkus.security.jaxrs.deny-unannotated-endpoints" or "quarkus.security.jaxrs.default-rol ... [quarkus-2.13]
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0494?
The severity of RHSA-2024:0494 is classified as important.
How do I fix RHSA-2024:0494?
To fix RHSA-2024:0494, update your Red Hat Build of Quarkus to version 2.13.9.SP1.
What software does RHSA-2024:0494 affect?
RHSA-2024:0494 affects the Red Hat Build of Quarkus.
What are the main changes in RHSA-2024:0494?
RHSA-2024:0494 includes security updates, bug fixes, and enhancements.
When was RHSA-2024:0494 released?
RHSA-2024:0494 was released as a security update for Red Hat Build of Quarkus.