RedHat: RHSA-2023-3740:01 Important: Red Hat Integration Camel for Spring
Summary
This release of Camel for Spring Boot 3.20.1.P1 serves as a replacement for
Camel for Spring Boot 3.20.1 and includes bug fixes and enhancements, which
are documented in the Release Notes linked in the References. The purpose
of this text-only errata is to inform you about the security issues fixed.
Security Fix(es):
* vertx-web: StaticHandler disclosure of classpath resources on Windows
when mounted on a wildcard route (CVE-2023-24815)
* spring-boot: Spring Boot Welcome Page DoS Vulnerability (CVE-2023-20883)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Summary
Solution
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
References
https://access.redhat.com/security/cve/CVE-2023-20883 https://access.redhat.com/security/cve/CVE-2023-24815 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2023-Q2
Package List
Topic
Red Hat Integration Camel for Spring Boot 3.20.1 Patch 1 release andsecurity update is now available.Red Hat Product Security has rated this update as having an impact ofImportant. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Topic
Relevant Releases Architectures
Bugs Fixed
2209342 - CVE-2023-20883 spring-boot: Spring Boot Welcome Page DoS Vulnerability
2209400 - CVE-2023-24815 vertx-web: StaticHandler disclosure of classpath resources on Windows when mounted on a wildcard route