-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Important: Red Hat Integration Camel Extensions For Quarkus 2.13.2-2 security update
Advisory ID:       RHSA-2023:3179-01
Product:           Red Hat Integration
Advisory URL:      https://access.redhat.com/errata/RHSA-2023:3179
Issue date:        2023-05-17
CVE Names:         CVE-2023-1370 
====================================================================
1. Summary:

Red Hat Integration Camel Extensions for Quarkus 2.13.2-2 release and
security update is now available. The purpose of this text-only errata is
to inform you about the security issues fixed.

Red Hat Product Security has rated this update as having an impact of
Important. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Description:

A security update for Camel Extensions for Quarkus 2.13.2-2 is now
available. The purpose of this text-only errata is to inform you about the
security issues fixed.

Security Fix(es):

* json-smart: Uncontrolled Resource Consumption vulnerability in json-smart
(Resource Exhaustion) (CVE-2023-1370)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

Before applying the update, back up your existing installation, including
all applications, configuration files, databases and database settings, and
so on.

The References section of this erratum contains a download link (you must
log in to download the update).

4. Bugs fixed (https://bugzilla.redhat.com/):

2188542 - CVE-2023-1370 json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion)

5. References:

https://access.redhat.com/security/cve/CVE-2023-1370
https://access.redhat.com/security/updates/classification/#important
https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2023-Q2

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBZGUUlNzjgjWX9erEAQg5ZQ//VLp3h0qYtn+T+CRXNNGUmWidLP2g0udw
dCDTM5JPvQZXOxVBgFXQlxhmo/EqY2SRTAVf+v1e7YK3g4Zzwpkf0eK4BDk8LVuA
4lTMvL0PxWmk0Th68qRFoy4gtRnrBTPg02wwi/EGdD9DvOAUCB+SnBRQA+p2fd5c
itRA/Z/w6sQNukYgGv4fP9H/c4Werjpgn0RY21z8UXAXkJZRt9qp3ilKvZawfr0X
xERjE+tmhj1QFqWriSBFFpG9xvKFoeUD+Oozxu6q+1d6BfRMPUnR0JWGoiI7JZd5
VD0Bto4YrmQKTv16e9JqBYCEEYfbfv6rQSyUKAghBFDg24tkKu6YcyQwsNpZM8Re
XlBV5FRFBOvNjUT8UW3VXHyt4OARAbAaIInSgWF4nP0dCyhIuCPzdSglOvUuU4cy
xhRUxhhJ1i2NA6541yCBQrExTnuPYaLQQrhnYghCNLZhr1JdvRwO9dWSBxajrb1M
WcVKdOzqMZ4piq38s7uOVh2m159daX6v0jQDcWPqYd2rMCuVy4Mc+Ee2j7Uonf7o
higxE/WpQiiX1KfPNtX1dEI/fGUI+inFyJFK6ZnGdxAISXXCh4G7xEkhtNVAKLWq
IQzVrxmsxbixb6UYyMsQ2z9iCPbF8iL4mO887mE6pR74ZOBIV1EpleXWgdWurmt0
4XPHD7Ui0yk=R0dS
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2023-3179:01 Important: Red Hat Integration Camel Extensions

Red Hat Integration Camel Extensions for Quarkus 2.13.2-2 release and security update is now available

Summary

A security update for Camel Extensions for Quarkus 2.13.2-2 is now available. The purpose of this text-only errata is to inform you about the security issues fixed.
Security Fix(es):
* json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) (CVE-2023-1370)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.
The References section of this erratum contains a download link (you must log in to download the update).

References

https://access.redhat.com/security/cve/CVE-2023-1370 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2023-Q2

Package List


Severity
Advisory ID: RHSA-2023:3179-01
Product: Red Hat Integration
Advisory URL: https://access.redhat.com/errata/RHSA-2023:3179
Issued Date: : 2023-05-17
CVE Names: CVE-2023-1370

Topic

Red Hat Integration Camel Extensions for Quarkus 2.13.2-2 release andsecurity update is now available. The purpose of this text-only errata isto inform you about the security issues fixed.Red Hat Product Security has rated this update as having an impact ofImportant. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

2188542 - CVE-2023-1370 json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion)


Related News