RHSA-2024:0495: Important: Red Hat build of Quarkus 3.2.9.SP1 release and security update
Important: Red Hat build of Quarkus 3.2.9.SP1 release and security update
Other sources
This release of Red Hat build of Quarkus 3.2.9.SP1 includes security updates, bug fixes, and enhancements. For more information, see the release notes page listed in the References section.Security Fix(es): CVE-2023-5675 io.quarkus.resteasy.reactive/resteasy-reactive: quarkus: Authorization flaw in Quarkus RestEasy Reactive and Classic when "quarkus.security.jaxrs.deny-unannotated-endpoints" or "quarkus.security.jaxrs.default-role [quarkus-3.2] CVE-2023-6267 io.quarkus.resteasy.reactive/resteasy-reactive: quarkus: json payload getting processed prior to security checks when rest resources are used with annotations [quarkus-3.2]
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0495?
The severity of RHSA-2024:0495 is classified as Important.
How do I fix RHSA-2024:0495?
To fix RHSA-2024:0495, upgrade to Red Hat build of Quarkus version 3.2.9.SP1 or later.
What vulnerabilities are addressed in RHSA-2024:0495?
RHSA-2024:0495 addresses multiple security vulnerabilities found in previous versions of Red Hat build of Quarkus.
What new features are included in RHSA-2024:0495?
RHSA-2024:0495 includes bug fixes, security updates, and enhancements to improve functionality.
Which software is affected by RHSA-2024:0495?
RHSA-2024:0495 affects the Red Hat Build of Quarkus software.