Red Hat Security Advisory: Red Hat Build of Apache Camel 3.20.6 for Spring Boot security update.
🔗 CVE IDs covered (6)
📋 Description
CVE-2022-34169 — OpenJDK: integer truncation issue in Xalan-J (JAXP, 8285407) CVE-2022-45685 — jettison: stack overflow in JSONObject() allows attackers to cause a Denial of Service (DoS) via crafted JSON data CVE-2023-44483 — santuario: Private Key disclosure in debug-log output CVE-2024-22257 — spring-security: Broken Access Control With Direct Use of AuthenticatedVoter CVE-2024-22262 — springframework: URL Parsing with Host Validation CVE-2024-28752 — cxf-core: Apache CXF SSRF Vulnerability using the Aegis databinding
🎯 Affected products1
- Red Hat build of Apache Camel 3.20.6 for Spring Boot
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: No mitigation is currently available for this vulnerability. Please make sure to update as the fixes become available.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2024:3708
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2108554
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2214825
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2246070
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270732
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2275257
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_3708.json