RHSA-2022:1029HighCVSS 8.8

Red Hat Security Advisory: Red Hat Integration Camel-K 1.6.4 release and security update

Published
March 23, 2022
Last Modified
August 4, 2026

🔗 CVE IDs covered (11)

📋 Description

CVE-2020-8908 — guava: local information disclosure via temporary directory created with unsafe permissions CVE-2020-15522 — bouncycastle: Timing issue within the EC math library CVE-2020-27218 — jetty: buffer not correctly recycled in Gzip Request inflation CVE-2021-3690 — undertow: buffer leak on incoming websocket PONG message may lead to DoS CVE-2021-20293 — RESTEasy: PathParam in RESTEasy can lead to a reflected XSS attack CVE-2021-21349 — XStream: SSRF can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host CVE-2021-26291 — maven: Block repositories using http by default CVE-2021-28168 — jersey: Local information disclosure via system temporary directory CVE-2021-28170 — jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate CVE-2021-33813 — jdom: XXE allows attackers to cause a DoS via a crafted HTTP request CVE-2022-24407 — cyrus-sasl: failure to properly escape SQL input allows an attacker to execute arbitrary SQL commands

🎯 Affected products1

  • RHINT Camel-K 1.6.4

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To avoid possible man-in-the-middle related attacks with this flaw, ensure any linked repositories in maven POMs use https and not http.

🔗 References (16)