Red Hat Security Advisory: Red Hat Camel for Spring Boot 3.14.5 Patch 1 release and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2022-40149 — jettison: parser crash by stackoverflow CVE-2022-45693 — jettison: If the value in map is the map's self, the new new JSONObject(map) cause StackOverflowError which may lead to dos CVE-2022-46363 — CXF: directory listing / code exfiltration CVE-2022-46364 — CXF: SSRF Vulnerability
🎯 Affected products1
- RHINT Camel-Springboot 3.14.5.P1
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. Installation instructions are available from the Camel for Spring Boot 3.14.5 product documentation page. https://access.redhat.com/documentation/en-us/red_hat_integration/2023.q1/html/getting_started_with_camel_spring_boot/index https://access.redhat.com/documentation/en-us/red_hat_integration/2023.q1/html/camel_spring_boot_reference/index
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2023:0544
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2023-Q1
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2135771
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2155681
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2155682
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2155970
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0544.json