RHSA-2021:0811LowCVSS 7.5
Red Hat Security Advisory: Red Hat Integration Tech-Preview 3 Camel K security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2020-13946 — cassandra: allows manipulation of the RMI registry to perform a MITM attack and capture user names and passwords used to access the JMX interface CVE-2020-13956 — apache-httpclient: incorrect handling of malformed authority component in request URIs CVE-2020-25649 — jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE)
🎯 Affected products1
- Red Hat Integration - Camel K - Tech-Preview 3
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: There is currently no known mitigation for this flaw.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2021:0811
- externalhttps://access.redhat.com/security/updates/classification/#low
- externalhttps://access.redhat.com/documentation/en-us/red_hat_integration/2021.q1/html-single/release_notes_for_red_hat_integration_2021.q1
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1875830
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1886587
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1887664
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_0811.json