Red Hat Security Advisory: Red Hat Integration Camel Extensions For Quarkus 2.13.2
🔗 CVE IDs covered (11)
📋 Description
CVE-2022-40149 — jettison: parser crash by stackoverflow CVE-2022-40150 — jettison: memory exhaustion via user-supplied XML or JSON data CVE-2022-40151 — xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks CVE-2022-40152 — woodstox-core: woodstox to serialise XML data was vulnerable to Denial of Service attacks CVE-2022-40153 — xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks CVE-2022-40154 — xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks CVE-2022-40155 — xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks CVE-2022-40156 — xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks CVE-2022-42003 — jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS CVE-2022-42004 — jackson-databind: use of deeply nested arrays CVE-2022-42889 — apache-commons-text: variable interpolation RCE
🎯 Affected products1
- RHINT Camel-Q 2.13.2
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: This flaw may be avoided by ensuring that any external inputs used with the Commons-Text lookup methods are sanitized properly. Untrusted input should always be thoroughly sanitized before using in any potentially risky situations.
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2023:0469
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2023-Q1
- externalhttps://access.redhat.com/documentation/en-us/red_hat_integration/2023.q1
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2128959
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134288
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134289
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134290
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134291
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134292
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2135244
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2135247
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2135435
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2135770
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2135771
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0469.json