Red Hat Security Advisory: Red Hat Build of Apache Camel 4.8.5 for Spring Boot security update.
🔗 CVE IDs covered (5)
📋 Description
CVE-2024-57699 — json-smart: Potential DoS via stack exhaustion (incomplete fix for CVE-2023-1370) CVE-2025-2240 — smallrye-fault-tolerance: SmallRye Fault Tolerance CVE-2025-22228 — spring-security-core: Spring Security BCryptPasswordEncoder does not enforce maximum password length CVE-2025-24970 — io.netty:netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine CVE-2025-27636 — camel-http: org.apache.camel: bypass of header filters via specially crafted response
🎯 Affected products1
- Red Hat build of Apache Camel 4.8.5 for Spring Boot
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat Product Security does not have a recommended mitigation at this time. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Remove headers from your Camel routes; this can be accomplished in several ways, including globally or per route.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2025:3543
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2344073
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2344787
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2350682
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2351452
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2353507
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_3543.json