RHSA-2022:8902MediumCVSS 9.8

Red Hat Security Advisory: Red Hat Camel for Spring Boot 3.18.3 release and security update

Published
December 8, 2022
Last Modified
August 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2022-25897 — sdk-server: Denial of Service CVE-2022-31684 — reactor-netty-http: Log request headers in some cases of invalid HTTP requests CVE-2022-42889 — apache-commons-text: variable interpolation RCE

🎯 Affected products1

  • RHINT Camel-Springboot 3.18.3

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. Installation instructions are available from the Camel for Spring Boot 3.18.3 product documentation page. https://access.redhat.com/documentation/en-us/red_hat_integration/2022.q4/html/getting_started_with_camel_spring_boot/index https://access.redhat.com/documentation/en-us/red_hat_integration/2022.q4/html/camel_spring_boot_reference/index Workaround: This flaw may be avoided by ensuring that any external inputs used with the Commons-Text lookup methods are sanitized properly. Untrusted input should always be thoroughly sanitized before using in any potentially risky situations.

🔗 References (7)