Red Hat Security Advisory: Red Hat Integration Camel-K 1.6.4 release and security update
🔗 CVE IDs covered (11)
📋 Description
CVE-2020-8908 — guava: local information disclosure via temporary directory created with unsafe permissions CVE-2020-15522 — bouncycastle: Timing issue within the EC math library CVE-2020-27218 — jetty: buffer not correctly recycled in Gzip Request inflation CVE-2021-3690 — undertow: buffer leak on incoming websocket PONG message may lead to DoS CVE-2021-20293 — RESTEasy: PathParam in RESTEasy can lead to a reflected XSS attack CVE-2021-21349 — XStream: SSRF can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host CVE-2021-26291 — maven: Block repositories using http by default CVE-2021-28168 — jersey: Local information disclosure via system temporary directory CVE-2021-28170 — jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate CVE-2021-33813 — jdom: XXE allows attackers to cause a DoS via a crafted HTTP request CVE-2022-24407 — cyrus-sasl: failure to properly escape SQL input allows an attacker to execute arbitrary SQL commands
🎯 Affected products1
- RHINT Camel-K 1.6.4
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To avoid possible man-in-the-middle related attacks with this flaw, ensure any linked repositories in maven POMs use https and not http.
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2022:1029
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2022-Q2
- externalhttps://access.redhat.com/documentation/en-us/red_hat_integration/2022.q2
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1902826
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1906919
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1942635
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1942819
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1953024
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1955739
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1962879
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1965497
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1973413
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1991299
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2055326
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_1029.json