RHSA-2025:8761HighCVSS 7.5

Red Hat Security Advisory: HawtIO 4.2.0 for Red Hat build of Apache Camel 4 Release and security update.

Published
June 10, 2025
Last Modified
September 14, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2024-12397 — io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling CVE-2024-52798 — path-to-regexp: path-to-regexp Unpatched path-to-regexp ReDoS in 0.1.x CVE-2024-57699 — json-smart: Potential DoS via stack exhaustion (incomplete fix for CVE-2023-1370) CVE-2025-22866 — crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec CVE-2025-24970 — io.netty:netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine

🎯 Affected products1

  • HawtIO HawtIO 4.2.0

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Currently, no mitigation is available for this vulnerability. Workaround: Avoid using two parameters within a single path segment when the separator is not, for example, /:a-:b. Alternatively, you can define the regex used for both parameters and ensure they do not overlap to allow backtracking. Workaround: Red Hat Product Security does not have a recommended mitigation at this time. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (8)