Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Red Hat Quarkus 1.11.6 RHSA-2021-1004-01 Moderate: Remote Code Injection

red hat
Calendar Grey March 29, 2021
Dist Redhat Esm H88
Caution advised for users of Red Hat Quarkus version 1.11.6 due to potential injection vulnerabilities. Ensure that all systems are updated to the latest patches to mitigate risks effectively.
An update is now available for Red Hat build of Quarkus

Solution

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.

The References section of this erratum contains a download link for the update. You must be logged in to download the update.

Summary

This release of Red Hat build of Quarkus 1.11.6 includes security updates, bug fixes, and enhancements. For more information, see the release notes page listed in the References section.
Security Fix(es):
* cron-utils: template injection allows attackers to inject arbitrary Java EL expressions leading to remote code execution (CVE-2020-26238)
* resteasy-client: potential sensitive information leakage in JAX-RS RESTEasy Client's WebApplicationException handling (CVE-2020-25633)
* fabric8-kubernetes-client: vulnerable to a path traversal leading to integrity and availability compromise (CVE-2021-20218)
* resteasy: information disclosure via HTTP response reuse (CVE-2020-25724)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgements, and other related information, refer to the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2020-25633 https://access.redhat.com/security/cve/CVE-2020-25724 https://access.redhat.com/security/cve/CVE-2020-26238 https://access.redhat.com/security/cve/CVE-2021-20218 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=redhat.quarkus&downloadType=distributions&version=1.11.6 https://access.redhat.com/documentation/en-us/red_hat_build_of_quarkus/1.11/ https://access.redhat.com/articles/4966181

Package List


Advisory ID: RHSA-2021:1004-01
Product: Red Hat build of Quarkus
Issue date: 2021-03-29

Topic

An update is now available for Red Hat build of Quarkus.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability. Formore information, see the CVE links in the References section.

Relevant Releases Architectures

Bugs Fixed

1879042 - CVE-2020-25633 resteasy-client: potential sensitive information leakage in JAX-RS RESTEasy Client's WebApplicationException handling

1899354 - CVE-2020-25724 resteasy: information disclosure via HTTP response reuse

1901655 - CVE-2020-26238 cron-utils: template injection allows attackers to inject arbitrary Java EL expressions leading to remote code execution

1923405 - CVE-2021-20218 fabric8-kubernetes-client: vulnerable to a path traversal leading to integrity and availability compromise

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here