The following advisory data is extracted from: https://access.redhat.com/security/data/csaf/v2/advisories/2024/rhsa-2024_6437.json Red Hat officially shut down their mailing list notifications October 10, 2023. Due to this, Packet Storm has recreated the below data as a reference point to raise awareness. It must be noted that due to an inability to easily track revision updates without crawling Red Hat's archive, these advisories are single notifications and we strongly suggest that you visit the Red Hat provided links to ensure you have the latest information available if the subject matter listed pertains to your environment. - Packet Storm Staff ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat build of Quarkus 3.8.6 release and security update Advisory ID: RHSA-2024:6437-03 Product: Red Hat build of Quarkus Advisory URL: https://access.redhat.com/errata/RHSA-2024:6437 Issue date: 2024-09-23 Revision: 03 CVE Names: CVE-2024-3653 ==================================================================== Summary: An update is now available for Red Hat build of Quarkus. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. For more information, see the CVE links in the References section. Description: This release of Red Hat build of Quarkus 3.8.6 includes security updates, bug fixes, and enhancements. For more information, see the release notes page listed in the References section. Security Fix(es): * EMBARGOED CVE-2024-3653 io.quarkus/quarkus-undertow: undertow: LearningPushHandler can lead to remote memory DoS attacks [quarkus-3.8] * CVE-2024-8391 io.vertx.vertx-grpc-client: Vertx gRPC server does not limit the maximum message size [quarkus-3.8] * CVE-2024-8391 io.vertx.vertx-grpc-server: Vertx gRPC server does not limit the maximum message size [quarkus-3.8] Solution: https://access.redhat.com/articles/11258 CVEs: CVE-2024-3653 References: https://access.redhat.com/security/updates/classification/#moderate https://docs.redhat.com/en/documentation/red_hat_build_of_quarkus/3.8 https://access.redhat.com/articles/4966181 https://issues.redhat.com/browse/QUARKUS-4213 https://issues.redhat.com/browse/QUARKUS-4477 https://issues.redhat.com/browse/QUARKUS-4521 https://issues.redhat.com/browse/QUARKUS-4570 https://issues.redhat.com/browse/QUARKUS-4581 https://issues.redhat.com/browse/QUARKUS-4616 https://issues.redhat.com/browse/QUARKUS-4694 https://issues.redhat.com/browse/QUARKUS-4784 https://issues.redhat.com/browse/QUARKUS-4785 https://issues.redhat.com/browse/QUARKUS-4786 https://issues.redhat.com/browse/QUARKUS-4787 https://issues.redhat.com/browse/QUARKUS-4788 https://issues.redhat.com/browse/QUARKUS-4791 https://issues.redhat.com/browse/QUARKUS-4796 https://issues.redhat.com/browse/QUARKUS-4798 https://issues.redhat.com/browse/QUARKUS-4799 https://issues.redhat.com/browse/QUARKUS-4802 https://issues.redhat.com/browse/QUARKUS-4804 https://issues.redhat.com/browse/QUARKUS-4805 https://issues.redhat.com/browse/QUARKUS-4806 https://issues.redhat.com/browse/QUARKUS-4807 https://issues.redhat.com/browse/QUARKUS-4808 https://issues.redhat.com/browse/QUARKUS-4809 https://issues.redhat.com/browse/QUARKUS-4810 https://issues.redhat.com/browse/QUARKUS-4814 https://issues.redhat.com/browse/QUARKUS-4815 https://issues.redhat.com/browse/QUARKUS-4816 https://issues.redhat.com/browse/QUARKUS-4817 https://issues.redhat.com/browse/QUARKUS-4818 https://issues.redhat.com/browse/QUARKUS-4819 https://issues.redhat.com/browse/QUARKUS-4820 https://issues.redhat.com/browse/QUARKUS-4822 https://issues.redhat.com/browse/QUARKUS-4826 https://issues.redhat.com/browse/QUARKUS-4827 https://issues.redhat.com/browse/QUARKUS-4828 https://issues.redhat.com/browse/QUARKUS-4829 https://issues.redhat.com/browse/QUARKUS-4830 https://issues.redhat.com/browse/QUARKUS-4831 https://issues.redhat.com/browse/QUARKUS-4834 https://issues.redhat.com/browse/QUARKUS-4835 https://issues.redhat.com/browse/QUARKUS-4836 https://issues.redhat.com/browse/QUARKUS-4837 https://issues.redhat.com/browse/QUARKUS-4838 https://issues.redhat.com/browse/QUARKUS-4839 https://issues.redhat.com/browse/QUARKUS-4841 https://issues.redhat.com/browse/QUARKUS-4842 https://issues.redhat.com/browse/QUARKUS-4844 https://issues.redhat.com/browse/QUARKUS-4846 https://issues.redhat.com/browse/QUARKUS-4847 https://issues.redhat.com/browse/QUARKUS-4848 https://issues.redhat.com/browse/QUARKUS-4849 https://issues.redhat.com/browse/QUARKUS-4850 https://issues.redhat.com/browse/QUARKUS-4853 https://issues.redhat.com/browse/QUARKUS-4854 https://issues.redhat.com/browse/QUARKUS-4855