Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Red Hat: RHSA-2023-0544 Important: Camel Spring Boot 3.14.5 Security Update

red hat
Calendar Grey January 30, 2023
Scroller Redhat
A critical security patch for Red Hat Camel Spring Boot resolves multiple important vulnerabilities affecting the software.
A patch is now available for Camel for Spring Boot 3.14.5

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

Installation instructions are available from the Camel for Spring Boot 3.14.5 product documentation page.

https://access.redhat.com/documentation/en-us/red_hat_integration/2023.q1/html/getting_started_with_camel_spring_boot/index


Summary

This patch, Camel for Spring Boot 3.14.5 Patch 1, serves as a replacement for the previous release of Camel for Spring Boot 3.14.5 and includes bug fixes and enhancements, which are documented in the Release Notes document linked in the References. This release of Camel for Spring Boot includes CXF artifacts that were missing from the previous 3.14.5 release.
Security Fix(es):
* CXF: Apache CXF: SSRF Vulnerability (CVE-2022-46364)
* jettison: parser crash by stackoverflow (CVE-2022-40149)
* jettison: If the value in map is the map's self, the new JSONObject(map) cause StackOverflowError which may lead to dos (CVE-2022-45693)
* CXF: Apache CXF: directory listing / code exfiltration (CVE-2022-46363)
For more details about the security issues, including the impact, CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2022-40149 https://access.redhat.com/security/cve/CVE-2022-45693 https://access.redhat.com/security/cve/CVE-2022-46363 https://access.redhat.com/security/cve/CVE-2022-46364 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2023-Q1

Package List


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2023:0544-01
Product: Red Hat Integration
Issue date: 2023-01-30

Topic

A patch is now available for Camel for Spring Boot 3.14.5. The purpose ofthis text-only errata is to inform you about the security issues fixed inthis release.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures

Bugs Fixed

2135771 - CVE-2022-40149 jettison: parser crash by stackoverflow

2155681 - CVE-2022-46363 Apache CXF: directory listing / code exfiltration

2155682 - CVE-2022-46364 Apache CXF: SSRF Vulnerability

2155970 - CVE-2022-45693 jettison: If the value in map is the map's self, the new new JSONObject(map) cause StackOverflowError which may lead to dos

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.