RHSA-2023:0469MediumCVSS 9.8

Red Hat Security Advisory: Red Hat Integration Camel Extensions For Quarkus 2.13.2

Published
January 26, 2023
Last Modified
August 4, 2026

🔗 CVE IDs covered (11)

CVE-2022-40149CVE-2022-40153 · pendingCVE-2022-40154 · pendingCVE-2022-40156 · pendingCVE-2022-40150CVE-2022-40151CVE-2022-40152CVE-2022-40155 · pendingCVE-2022-42003CVE-2022-42004CVE-2022-42889

📋 Description

CVE-2022-40149 — jettison: parser crash by stackoverflow CVE-2022-40150 — jettison: memory exhaustion via user-supplied XML or JSON data CVE-2022-40151 — xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks CVE-2022-40152 — woodstox-core: woodstox to serialise XML data was vulnerable to Denial of Service attacks CVE-2022-40153 — xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks CVE-2022-40154 — xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks CVE-2022-40155 — xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks CVE-2022-40156 — xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks CVE-2022-42003 — jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS CVE-2022-42004 — jackson-databind: use of deeply nested arrays CVE-2022-42889 — apache-commons-text: variable interpolation RCE

🎯 Affected products1

  • RHINT Camel-Q 2.13.2

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: This flaw may be avoided by ensuring that any external inputs used with the Commons-Text lookup methods are sanitized properly. Untrusted input should always be thoroughly sanitized before using in any potentially risky situations.

🔗 References (16)