-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Critical: Red Hat Integration Camel Extensions for Quarkus GA security update
Advisory ID:       RHSA-2021:5126-01
Product:           Red Hat Integration
Advisory URL:      https://access.redhat.com/errata/RHSA-2021:5126
Issue date:        2021-12-14
CVE Names:         CVE-2021-44228 
====================================================================
1. Summary:

A security update to Red Hat Integration Camel Extensions for Quarkus 2.2
is now available. The purpose of this text-only errata is to inform you
about the security issues fixed.

Red Hat Product Security has rated this update as having a security impact
of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Description:

This update of Red Hat Integration - Camel Extensions for Quarkus serves as
a replacement for 2.2 GA and includes the following security Fix(es):

* log4j-core: Remote code execution in Log4j 2.x when logs contain an
attacker-controlled string value (CVE-2021-44228)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

4. Bugs fixed (https://bugzilla.redhat.com/):

2030932 - CVE-2021-44228 log4j-core: Remote code execution in Log4j 2.x when logs contain an attacker-controlled string value

5. References:

https://access.redhat.com/security/cve/CVE-2021-44228
https://access.redhat.com/security/updates/classification/#critical
https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2021-Q4
https://access.redhat.com/documentation/en-us/red_hat_integration/2021.q4
https://access.redhat.com/security/vulnerabilities/RHSB-2021-009

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2021 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBYbj07NzjgjWX9erEAQjHaxAAoAdIdVkUQa6o4vyn1hVB8EMXg7XGMfXu
F9FgkkRGVk90xoaqbdUIFbkeLxDcVJT2DXE2bJoz+rej8C3s8ywPN8+mdMkeXvLG
z0UsAgpcF1IW9H05AI2EwZ9Zc81WNfKq57QhHLYppOLDwrCAeT4Eb+1W1TO1SjA8
ztkqyDOYibMbWWd0fNqz01VWlxjKhcK453edgi50vVHz5lMczewb+FxaWwJxxyMw
Zr/T4J40quDwep/PKQlGKgDq5BwWvpUNrcdb0xcXr2kQmbfmu2u/qUjxKHV9sZqx
E2dNNiJmUPufINPcyv3bEN7opOy+a8ISkw22bjDiJsXaO6Ogwf+5qLpsLjdP/Y8B
vKC0zjYuCuCyDBwVNs3Aq+HqKW1osRZNTRxTGex+aqCabFc6CHmpjSs/cEcfQ+IY
FScBadr2wlYMIWmzo93QonqKNPdWxtI6WI/uhM2hS+88NgvdAUJsPnneVM348K2p
46aYtfqdU4iigx3SUiPgDYu7sI3Cb4gwyOsUNdmnQhc9Tx5qjm4U7iytJQHF9+Wt
usCLQsj29nh9wnCYV4Sho3juWJ55GKpPT2Ys767WkwdM20FohRiZ+Hcg+W3H83qT
brQSMR3HhKI4LmjD8th5zahVGuZJPUXkC/TEDlRu4+G1anD9q6gl43kwu31D8wyL
DZONdv3Giz0=ngv/
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2021-5126:01 Critical: Red Hat Integration Camel Extensions

A security update to Red Hat Integration Camel Extensions for Quarkus 2.2 is now available

Summary

This update of Red Hat Integration - Camel Extensions for Quarkus serves as a replacement for 2.2 GA and includes the following security Fix(es):
* log4j-core: Remote code execution in Log4j 2.x when logs contain an attacker-controlled string value (CVE-2021-44228)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2021-44228 https://access.redhat.com/security/updates/classification/#critical https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2021-Q4 https://access.redhat.com/documentation/en-us/red_hat_integration/2021.q4 https://access.redhat.com/security/vulnerabilities/RHSB-2021-009

Package List


Severity
Advisory ID: RHSA-2021:5126-01
Product: Red Hat Integration
Advisory URL: https://access.redhat.com/errata/RHSA-2021:5126
Issued Date: : 2021-12-14
CVE Names: CVE-2021-44228

Topic

A security update to Red Hat Integration Camel Extensions for Quarkus 2.2is now available. The purpose of this text-only errata is to inform youabout the security issues fixed.Red Hat Product Security has rated this update as having a security impactof Critical. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

2030932 - CVE-2021-44228 log4j-core: Remote code execution in Log4j 2.x when logs contain an attacker-controlled string value


Related News