RHSA-2025:3543HighCVSS 7.5
Red Hat Security Advisory: Red Hat Build of Apache Camel 4.8.5 for Spring Boot security update.
🔗 CVE IDs covered (5)
📋 Description
CVE-2024-57699 — json-smart: Potential DoS via stack exhaustion (incomplete fix for CVE-2023-1370) CVE-2025-2240 — smallrye-fault-tolerance: SmallRye Fault Tolerance CVE-2025-22228 — spring-security-core: Spring Security BCryptPasswordEncoder does not enforce maximum password length CVE-2025-24970 — io.netty:netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine CVE-2025-27636 — camel-http: org.apache.camel: bypass of header filters via specially crafted response
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2025:3543
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2344073
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2344787
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2350682
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2351452
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2353507
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_3543.json