Red Hat Security Advisory: Red Hat build of Quarkus 2.13.9.SP2 release and security update
Red Hat has released a security update for Red Hat build of Quarkus 2.13.9.SP2 addressing three vulnerabilities: CVE-2024-1597, which allows SQL injection via the PostgreSQL JDBC Driver when using PreferQueryMode=SIMPLE; CVE-2024-25710, a denial of service caused by an infinite loop when processing corrupted DUMP files in Apache Commons Compress; and CVE-2024-26308, which can cause an OutOfMemoryError when unpacking broken Pack200 files in Apache Commons Compress. These issues are rated as important by Red Hat and are fixed in this update. Users should apply this update after ensuring all prior relevant errata are installed.
AI Analysis
Technical Summary
This advisory covers security fixes in Red Hat build of Quarkus 2.13.9.SP2. It addresses three vulnerabilities: CVE-2024-1597 in the PostgreSQL JDBC Driver (pgjdbc) that permits SQL injection if PreferQueryMode=SIMPLE is used; CVE-2024-25710 in Apache Commons Compress causing denial of service via an infinite loop triggered by corrupted DUMP files; and CVE-2024-26308 also in Apache Commons Compress causing an OutOfMemoryError when unpacking malformed Pack200 files. The update includes patches for these issues and is classified as important by Red Hat Product Security. No CVSS scores are provided in the advisory.
Potential Impact
Successful exploitation of CVE-2024-1597 could allow an attacker to perform SQL injection attacks via the PostgreSQL JDBC Driver under specific configuration, potentially compromising database integrity or confidentiality. CVE-2024-25710 can cause denial of service by triggering an infinite loop when processing corrupted DUMP files, impacting availability. CVE-2024-26308 can lead to an OutOfMemoryError when unpacking broken Pack200 files, also affecting availability. These vulnerabilities affect applications using the affected Quarkus build and its bundled libraries.
Mitigation Recommendations
Red Hat has released an official security update in Red Hat build of Quarkus 2.13.9.SP2 that addresses these vulnerabilities. Users should apply this update after confirming all previously released relevant errata are installed. No additional mitigations are specified or required beyond applying the official update.
Red Hat Security Advisory: Red Hat build of Quarkus 2.13.9.SP2 release and security update
Description
Red Hat has released a security update for Red Hat build of Quarkus 2.13.9.SP2 addressing three vulnerabilities: CVE-2024-1597, which allows SQL injection via the PostgreSQL JDBC Driver when using PreferQueryMode=SIMPLE; CVE-2024-25710, a denial of service caused by an infinite loop when processing corrupted DUMP files in Apache Commons Compress; and CVE-2024-26308, which can cause an OutOfMemoryError when unpacking broken Pack200 files in Apache Commons Compress. These issues are rated as important by Red Hat and are fixed in this update. Users should apply this update after ensuring all prior relevant errata are installed.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory covers security fixes in Red Hat build of Quarkus 2.13.9.SP2. It addresses three vulnerabilities: CVE-2024-1597 in the PostgreSQL JDBC Driver (pgjdbc) that permits SQL injection if PreferQueryMode=SIMPLE is used; CVE-2024-25710 in Apache Commons Compress causing denial of service via an infinite loop triggered by corrupted DUMP files; and CVE-2024-26308 also in Apache Commons Compress causing an OutOfMemoryError when unpacking malformed Pack200 files. The update includes patches for these issues and is classified as important by Red Hat Product Security. No CVSS scores are provided in the advisory.
Potential Impact
Successful exploitation of CVE-2024-1597 could allow an attacker to perform SQL injection attacks via the PostgreSQL JDBC Driver under specific configuration, potentially compromising database integrity or confidentiality. CVE-2024-25710 can cause denial of service by triggering an infinite loop when processing corrupted DUMP files, impacting availability. CVE-2024-26308 can lead to an OutOfMemoryError when unpacking broken Pack200 files, also affecting availability. These vulnerabilities affect applications using the affected Quarkus build and its bundled libraries.
Mitigation Recommendations
Red Hat has released an official security update in Red Hat build of Quarkus 2.13.9.SP2 that addresses these vulnerabilities. Users should apply this update after confirming all previously released relevant errata are installed. No additional mitigations are specified or required beyond applying the official update.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2024:1797
- Cve Count
- 3
- Additional Cves
- ["CVE-2024-25710","CVE-2024-26308"]
Threat ID: 6a1f4ea2e29bf47b500885b6
Added to database: 06/02/2026, 21:44:02 UTC
Last enriched: 06/29/2026, 00:10:38 UTC
Last updated: 09/10/2026, 19:36:47 UTC
Views: 120
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.