RedHat: RHSA-2023-3906:01 Important: Red Hat Integration Camel K 1.10.1
Summary
A security update for Camel K 1.10.1 is now available.
The purpose of this text-only errata is to inform you about the security
issues fixed with this release.
* json-smart: Uncontrolled Resource Consumption vulnerability in json-smart
(Resource Exhaustion)(CVE-2023-1370)
* codehaus-plexus: Directory Traversal (CVE-2022-4244)
* codehaus-plexus: XML External Entity (XXE) Injection (CVE-2022-4245)
* scandium: Failing DTLS handshakes may cause throttling to block
processing of records (CVE-2022-39368)
* jdbc-postgresql: postgresql-jdbc: Information leak of prepared statement
data due to insecure temporary file permissions (CVE-2022-41946)
* Apache CXF: directory listing / code exfiltration (CVE-2022-46363)
A Common Vulnerability Scoring System (CVSS) base score, which gives a
detailed severity rating, is available for each vulnerability from the CVE
link(s) in the References section.
Summary
Solution
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
References
https://access.redhat.com/security/cve/CVE-2022-4244 https://access.redhat.com/security/cve/CVE-2022-4245 https://access.redhat.com/security/cve/CVE-2022-39368 https://access.redhat.com/security/cve/CVE-2022-41946 https://access.redhat.com/security/cve/CVE-2022-46363 https://access.redhat.com/security/cve/CVE-2023-1370 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2023-Q2
Package List
Topic
Red Hat Integration Camel K 1.10.1 release and security update is nowavailable. The purpose of this text-only errata is to inform you about thesecurity issues fixed. Red Hat Product Security has rated this update ashaving an impact of Important.
Topic
Relevant Releases Architectures
Bugs Fixed
2145205 - CVE-2022-39368 scandium: Failing DTLS handshakes may cause throttling to block processing of records
2149841 - CVE-2022-4244 codehaus-plexus: Directory Traversal
2149843 - CVE-2022-4245 codehaus-plexus: XML External Entity (XXE) Injection
2153399 - CVE-2022-41946 postgresql-jdbc: Information leak of prepared statement data due to insecure temporary file permissions
2155681 - CVE-2022-46363 Apache CXF: directory listing / code exfiltration
2188542 - CVE-2023-1370 json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion)