RHSA-2022:6407MediumCVSS 8.8

Red Hat Security Advisory: Red Hat Integration Camel-K 1.8 security update

Published
September 9, 2022
Last Modified
August 7, 2026

🔗 CVE IDs covered (15)

📋 Description

CVE-2020-9492 — hadoop: WebHDFS client might send SPNEGO authorization header CVE-2020-27223 — jetty: request containing multiple Accept headers with a large number of "quality" parameters may lead to DoS CVE-2020-36518 — jackson-databind: denial of service via a large depth of nested objects CVE-2021-2471 — mysql-connector-java: unauthorized access to critical CVE-2021-3520 — lz4: memory corruption due to an integer overflow bug caused by memmove argument CVE-2021-3629 — undertow: potential security issue in flow control over HTTP/2 may lead to DOS CVE-2021-20289 — resteasy: Error message exposes endpoint class information CVE-2021-22132 — elasticsearch: executing async search improperly stores HTTP headers leading to information disclosure CVE-2021-22137 — elasticsearch: Document disclosure flaw when Document or Field Level Security is used CVE-2021-28163 — jetty: Symlink directory exposes webapp directory contents CVE-2021-28164 — jetty: Ambiguous paths can access WEB-INF CVE-2021-28165 — jetty: Resource exhaustion when receiving an invalid large TLS frame CVE-2021-37714 — jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck CVE-2021-38153 — Kafka: Timing Attack Vulnerability for Apache Kafka Connect and Clients CVE-2021-40690 — xml-security: XPath Transform abuse allows for information disclosure

🎯 Affected products1

  • RHAF Camel-K 1.8

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258

🔗 References (20)