RHSA-2024:7670: Critical: Red Hat build of Quarkus 3.8.6.SP1 Security Update
Critical: Red Hat build of Quarkus 3.8.6.SP1 Security Update
Other sources
This release of Red Hat build of Quarkus 3.8.6.SP1 contains security updates. For more information, see the release notespage listed in the References section.Security Fix(es): com.google.protobuf/protobuf: StackOverflow vulnerability in Protocol Buffers (CVE-2024-7254) org.eclipse.angus/angus-mail: Enabling Secure Server Identity Checks for Safer SMTPS Communication (CVE-2021-44549) com.graphql-java.graphql-java: Allocation of Resources Without Limits or Throttling in GraphQL Java (CVE-2024-40094) org.apache.avro/avro: Schema parsing may trigger Remote Code Execution (RCE) (CVE-2024-47561)
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:7670?
RHSA-2024:7670 is classified as a critical security update for Red Hat build of Quarkus.
How do I fix RHSA-2024:7670?
To fix RHSA-2024:7670, update to Red Hat build of Quarkus version 3.8.6.SP1 or later.
What vulnerabilities are addressed in RHSA-2024:7670?
RHSA-2024:7670 addresses security vulnerabilities related to com.google.protobuf/protobuf.
What software is affected by RHSA-2024:7670?
RHSA-2024:7670 affects the Red Hat build of Quarkus.
When was RHSA-2024:7670 released?
RHSA-2024:7670 was released as a security update for Red Hat build of Quarkus.