Red Hat Security Advisory: HawtIO 4.1.0 for Red Hat build of Apache Camel 4 Release and security update.
🔗 CVE IDs covered (9)
📋 Description
CVE-2024-2700 — quarkus-core: Leak of local configuration properties into Quarkus applications CVE-2024-4068 — braces: fails to limit the number of characters it can handle CVE-2024-7885 — undertow: Improper State Management in Proxy Protocol parsing causes information leakage CVE-2024-8184 — org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks CVE-2024-38816 — spring-webmvc: Path Traversal Vulnerability in Spring Applications Using RouterFunctions and FileSystemResource CVE-2024-43796 — express: Improper Input Handling in Express Redirects CVE-2024-43799 — send: Code Execution Vulnerability in Send Library CVE-2024-43800 — serve-static: Improper Sanitization in serve-static CVE-2024-45296 — path-to-regexp: Backtracking regular expressions cause ReDoS
🎯 Affected products1
- HawtIO 4.0.0 for Red Hat build of Apache Camel 4
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Currently, no mitigation is available for this vulnerability. Please update as the patches become available. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2024:11023
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2273281
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2280600
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2305290
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2310908
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2311152
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2311153
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2311154
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2312060
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2318564
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_11023.json