RHSA-2023:5147HighCVSS 9.8

Red Hat Security Advisory: Red Hat Integration Camel for Spring Boot 3.18.3.2 release and security update

Published
September 13, 2023
Last Modified
August 4, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2021-46877 — jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode CVE-2023-20873 — spring-boot: Security Bypass With Wildcard Pattern Matching on Cloud Foundry CVE-2023-33201 — bouncycastle: potential blind LDAP injection attack using a self-signed certificate CVE-2023-34455 — snappy-java: Unchecked chunk length leads to DoS

🎯 Affected products1

  • RHINT Camel-Springboot 3.18.3.2

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Disable Cloud Foundry actuator endpoints by setting 'management.cloudfoundry.enabled' to false.

🔗 References (8)