Skip to main content
EPSS 4.8%top 8.6%

Red Hat Security Advisory: Red Hat build of Quarkus 2.13.9.SP2 release and security update

0
High
Published: 04/22/2024 (04/22/2024, 10:59:06 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat has released a security update for Red Hat build of Quarkus 2.13.9.SP2 addressing three vulnerabilities: CVE-2024-1597, which allows SQL injection via the PostgreSQL JDBC Driver when using PreferQueryMode=SIMPLE; CVE-2024-25710, a denial of service caused by an infinite loop when processing corrupted DUMP files in Apache Commons Compress; and CVE-2024-26308, which can cause an OutOfMemoryError when unpacking broken Pack200 files in Apache Commons Compress. These issues are rated as important by Red Hat and are fixed in this update. Users should apply this update after ensuring all prior relevant errata are installed.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/29/2026, 00:10:38 UTC

Technical Analysis

This advisory covers security fixes in Red Hat build of Quarkus 2.13.9.SP2. It addresses three vulnerabilities: CVE-2024-1597 in the PostgreSQL JDBC Driver (pgjdbc) that permits SQL injection if PreferQueryMode=SIMPLE is used; CVE-2024-25710 in Apache Commons Compress causing denial of service via an infinite loop triggered by corrupted DUMP files; and CVE-2024-26308 also in Apache Commons Compress causing an OutOfMemoryError when unpacking malformed Pack200 files. The update includes patches for these issues and is classified as important by Red Hat Product Security. No CVSS scores are provided in the advisory.

Potential Impact

Successful exploitation of CVE-2024-1597 could allow an attacker to perform SQL injection attacks via the PostgreSQL JDBC Driver under specific configuration, potentially compromising database integrity or confidentiality. CVE-2024-25710 can cause denial of service by triggering an infinite loop when processing corrupted DUMP files, impacting availability. CVE-2024-26308 can lead to an OutOfMemoryError when unpacking broken Pack200 files, also affecting availability. These vulnerabilities affect applications using the affected Quarkus build and its bundled libraries.

Mitigation Recommendations

Red Hat has released an official security update in Red Hat build of Quarkus 2.13.9.SP2 that addresses these vulnerabilities. Users should apply this update after confirming all previously released relevant errata are installed. No additional mitigations are specified or required beyond applying the official update.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2024:1797
Cve Count
3
Additional Cves
["CVE-2024-25710","CVE-2024-26308"]

Threat ID: 6a1f4ea2e29bf47b500885b6

Added to database: 06/02/2026, 21:44:02 UTC

Last enriched: 06/29/2026, 00:10:38 UTC

Last updated: 09/10/2026, 19:36:47 UTC

Views: 120

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses