Before applying this update, make sure all previously released errata
relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
A security update for Camel Extensions for Quarkus 2.13.3 is now available.
The purpose of this text-only errata is to inform you about the security
issues fixed.
Red Hat Product Security has rated this update as having an impact of
Important.
A Common Vulnerability Scoring System (CVSS) base score, which gives a
detailed severity rating, is available for each vulnerability from the CVE
link(s) in the References section.
Security Fix(es):
* CVE-2023-1436 jettison: Uncontrolled Recursion in JSONArray
* CVE-2021-37533 apache-commons-net: FTP client trusts the host from
PASV response by default
https://access.redhat.com/security/cve/CVE-2021-37533 https://access.redhat.com/security/cve/CVE-2023-1436 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/security/cve/cve-2023-1436 https://access.redhat.com/security/cve/cve-2021-37533
Red Hat Integration Camel Extensions for Quarkus 2.13.3 release andsecurity update is now available. The purpose of this text-only errata isto inform you about the security issues fixed.Red Hat Product Security has rated this update as having an impact ofImportant.A Common Vulnerability Scoring System (CVSS) base score, which gives adetailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.
2169924 - CVE-2021-37533 apache-commons-net: FTP client trusts the host from PASV response by default
2182788 - CVE-2023-1436 jettison: Uncontrolled Recursion in JSONArray
Get the latest Linux and open source security news straight to your inbox.