RHSA-2024:1797: Important: Red Hat build of Quarkus 2.13.9.SP2 release and security update
Important: Red Hat build of Quarkus 2.13.9.SP2 release and security update
Other sources
This release of Red Hat build of Quarkus 2.13.9.SP2 includes security updates,<br>bug fixes, and enhancements. For more information, see the release notes page<br>listed in the References section.<br>Security Fix(es):<br><li> CVE-2024-1597 org.postgresql/postgresql: pgjdbc: PostgreSQL JDBC Driver allows attacker to inject SQL if using PreferQueryMode=SIMPLE [quarkus-2]</li> <li> CVE-2024-25710 org.apache.commons/commons-compress: Denial of service caused by an infinite loop for a corrupted DUMP file [quarkus-2]</li> <li> CVE-2024-26308 org.apache.commons/commons-compress: OutOfMemoryError unpacking broken Pack200 file [quarkus-2]</li>
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1797?
The severity of RHSA-2024:1797 is classified as important.
How do I fix RHSA-2024:1797?
To fix RHSA-2024:1797, update to the latest version of Red Hat build of Quarkus, specifically version 2.13.9.SP2.
What are the key updates included in RHSA-2024:1797?
RHSA-2024:1797 includes security updates, bug fixes, and performance enhancements for Red Hat build of Quarkus.
Which product is affected by RHSA-2024:1797?
The affected product for RHSA-2024:1797 is the Red Hat build of Quarkus.
What release version does RHSA-2024:1797 refer to?
RHSA-2024:1797 refers to the Red Hat build of Quarkus version 2.13.9.SP2.