exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Red Hat Security Advisory 2022-6941-01

Red Hat Security Advisory 2022-6941-01
Posted Oct 13, 2022
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2022-6941-01 - This release of Red Hat build of Quarkus 2.7.6.SP1 includes security updates, bug fixes, and enhancements. For more information, see the release notes page listed in the References section. Issues addressed include a denial of service vulnerability.

tags | advisory, denial of service
systems | linux, redhat
advisories | CVE-2022-25857
SHA-256 | 761f3b2e366b82b8d311e39873257989375f1240718119d1ae32f1467382ad95

Red Hat Security Advisory 2022-6941-01

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================
Red Hat Security Advisory

Synopsis: Important: Red Hat build of Quarkus Platform 2.7.6.SP1 and security update
Advisory ID: RHSA-2022:6941-01
Product: Red Hat build of Quarkus
Advisory URL: https://access.redhat.com/errata/RHSA-2022:6941
Issue date: 2022-10-13
CVE Names: CVE-2022-25857
====================================================================
1. Summary:

An update is now available for the Red Hat build of Quarkus Platform.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each
vulnerability. For more information, see the CVE links in the References
section.

2. Description:

This release of Red Hat build of Quarkus 2.7.6.SP1 (Service Pack 1)
includes security updates, bug fixes, and enhancements. For more
information, see the release notes page listed in the References section.

Security Fix(es):

* snakeyaml: Denial of Service due to missing nested depth limitation for
collections (CVE-2022-25857)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

Before applying the update, back up your existing installation, including
all applications, configuration files, databases and database settings, and
so on.

The References section of this erratum contains a download link for the
update. You must be logged in to download the update.

4. Bugs fixed (https://bugzilla.redhat.com/):

2126789 - CVE-2022-25857 snakeyaml: Denial of Service due to missing nested depth limitation for collections

5. References:

https://access.redhat.com/security/cve/CVE-2022-25857
https://access.redhat.com/security/updates/classification/#important
https://access.redhat.com/articles/4966181
https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=redhat.quarkus&version=2.7.6.SP1
https://access.redhat.com/documentation/en-us/red_hat_build_of_quarkus/2.7

6. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2022 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBY0gnI9zjgjWX9erEAQgR0A/+NjSPoaHYJeEnfyeRnIf1M+zqnwljZ4rz
mk6SZkqkFV4NWOlBIFQz5WhXvbs3DK0mx3FPlfisTybODHgYfrkV7D3IUq0rS4au
M2owZPnwT0GLnMgeNAq+8yT1ZGZ/d54AW3UF30A1UePoKU9WbfMmVPHdITeu2Rl1
hA1bC+opn9eF0OvCPWFbC9XlqHX4Dy04HNg4OSCY8AkIcH4ULg72sEwuTnAq9jly
HqF37FvxHr05OUoTlfxelxtye9fSjT2uyLHzn1uvnMbcPNX3l/YVNdcGu8Kq1hKp
nUW2735YaghlCzJUu7wzSh3tRqm1Zbq7VzZi1NGzeeSabBlosaqe9rNq4cF+t0eV
ORm5ORKpW8jflj4+DLhFUj6/D2TfcKxPylH5qLlVaLK2ly2wirwX3N9N15L6gRb2
NmhEBfvT30UOz+mjJyfkDGpGdO8uNSG094+HP9En8ekxIFzJs3khb7d1TeHOiGfu
CcMvgCx/sCCxTfZXfD57XXA6A1wVzBPy7PKXuIs5HjEFrCIlkkuJ9rc6Tq93jy+c
B++OTydsJg/3Q2Z9EnOBw/OPJbcAAzwLSNy3rznzc5nGuO5Pnr4Z7pJPH/D2xkH+
EIECFbqBvY0kdO2k9ILl2C4VUrJYHB9BmUxoMHaVYWY9vRzu9ZS+dqGH0cvnUhyP
58tlMzB+dBY=gVq4
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    0 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close