RHSA-2024:7676: Critical: Red Hat build of Quarkus 3.2.12.SP1 Security Update
Critical: Red Hat build of Quarkus 3.2.12.SP1 Security Update
Other sources
This release of Red Hat build of Quarkus 3.2.12.SP1 contains security updates. For more information, see the release notespage listed in the References section.Security Fix(es): com.google.protobuf/protobuf: StackOverflow vulnerability in Protocol Buffers (CVE-2024-7254) org.eclipse.angus/angus-mail: Enabling Secure Server Identity Checks for Safer SMTPS Communication (CVE-2021-44549) com.graphql-java.graphql-java: Allocation of Resources Without Limits or Throttling in GraphQL Java (CVE-2024-40094) org.apache.avro/avro: Schema parsing may trigger Remote Code Execution (RCE) (CVE-2024-47561)
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:7676?
RHSA-2024:7676 has been classified as critical due to significant security vulnerabilities.
How do I fix RHSA-2024:7676?
To resolve RHSA-2024:7676, update your Red Hat build of Quarkus to version 3.2.12.SP1 or later.
What vulnerabilities are addressed in RHSA-2024:7676?
RHSA-2024:7676 addresses security vulnerabilities related to the protobuf component.
Who is affected by RHSA-2024:7676?
All users running Red Hat build of Quarkus prior to version 3.2.12.SP1 are affected by RHSA-2024:7676.
Is there any risk if I don't address RHSA-2024:7676?
Not addressing RHSA-2024:7676 could expose your systems to critical security risks and potential exploits.