Red Hat Security Advisory: Red Hat Integration Camel-K 1.8 security update
🔗 CVE IDs covered (15)
📋 Description
CVE-2020-9492 — hadoop: WebHDFS client might send SPNEGO authorization header CVE-2020-27223 — jetty: request containing multiple Accept headers with a large number of "quality" parameters may lead to DoS CVE-2020-36518 — jackson-databind: denial of service via a large depth of nested objects CVE-2021-2471 — mysql-connector-java: unauthorized access to critical CVE-2021-3520 — lz4: memory corruption due to an integer overflow bug caused by memmove argument CVE-2021-3629 — undertow: potential security issue in flow control over HTTP/2 may lead to DOS CVE-2021-20289 — resteasy: Error message exposes endpoint class information CVE-2021-22132 — elasticsearch: executing async search improperly stores HTTP headers leading to information disclosure CVE-2021-22137 — elasticsearch: Document disclosure flaw when Document or Field Level Security is used CVE-2021-28163 — jetty: Symlink directory exposes webapp directory contents CVE-2021-28164 — jetty: Ambiguous paths can access WEB-INF CVE-2021-28165 — jetty: Resource exhaustion when receiving an invalid large TLS frame CVE-2021-37714 — jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck CVE-2021-38153 — Kafka: Timing Attack Vulnerability for Apache Kafka Connect and Clients CVE-2021-40690 — xml-security: XPath Transform abuse allows for information disclosure
🎯 Affected products1
- RHAF Camel-K 1.8
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
🔗 References (20)
- selfhttps://access.redhat.com/errata/RHSA-2022:6407
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2022-Q3
- externalhttps://access.redhat.com/documentation/en-us/red_hat_integration/2022.q3
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1923181
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1925237
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1934116
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1935927
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1943189
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1945710
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1945712
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1945714
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1954559
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1977362
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1995259
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2009041
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011190
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2020583
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2064698
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_6407.json