RHSA-2025:8761HighCVSS 7.5
Red Hat Security Advisory: HawtIO 4.2.0 for Red Hat build of Apache Camel 4 Release and security update.
🔗 CVE IDs covered (5)
📋 Description
CVE-2024-12397 — io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling
CVE-2024-52798 — path-to-regexp: path-to-regexp Unpatched path-to-regexp ReDoS in 0.1.x
CVE-2024-57699 — json-smart: Potential DoS via stack exhaustion (incomplete fix for CVE-2023-1370)
CVE-2025-22866 — crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec
CVE-2025-24970 — io.netty:netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2025:8761
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2330689
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2331298
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2344073
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2344219
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2344787
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_8761.json