Skip to main content

Threats Tagged 'cve-2024-9621'

View all threats tagged with 'cve-2024-9621'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2024-9621

Threats Tagged 'cve-2024-9621'

Click on any threat for detailed analysis and mitigation recommendations

A critical security update is available for Red Hat Build of Apache Camel 4.4 for Quarkus 3.8 (RHBQ 3.8.6.SP2). It addresses multiple vulnerabilities including CVE-2024-51132, which involves arbitrary code execution via specially-crafted FHIR requests, and CVE-2024-9621, where Quarkus CXF may log user passwords and secrets to application logs. The FHIR vulnerability stems from improper handling of XML external entities, potentially allowing attackers to execute code or access sensitive information. Red Hat notes that FHIR is out of support scope for this product and that the impact on Red Hat Fuse 7 is low due to non-utilization of the affected function. The update improves security and stability, and users are advised to back up their installations before applying it.

Join the discussion

A vulnerability was found in Quarkus CXF. Passwords and other secrets may appear in the application log in spite of the user configuring them to be hidden. This issue requires some special configuration to be vulnerable, such as SOAP logging enabled, application set client, and endpoint logging properties, and the attacker must have access to the application log.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: cve-2024-9621
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses