CVE-2022-0084: High severity redhat Integration Camel K vulnerability
A flaw was found in XNIO, specifically in the notifyReadClosed method. The issue revealed this method was logging a message to another expected end. This flaw allows an attacker to send flawed requests to a server, possibly causing log contention-related performance concerns or an unwanted disk fill-up.
Other sources
org.xnio.StreamConnection.notifyReadClosed log to debug instead of stderr
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-0084?
CVE-2022-0084 is a vulnerability found in XNIO, specifically in the notifyReadClosed method.
What is the severity of CVE-2022-0084?
The severity of CVE-2022-0084 is high with a CVSS score of 7.5.
How does CVE-2022-0084 affect the affected software?
CVE-2022-0084 affects the following software packages: eap7-jboss-xnio-base, rh-sso7-keycloak, rh-sso7, rh-sso7-javapackages-tools, Redhat Integration Camel K, Redhat Integration Camel Quarkus, Redhat Single Sign-on, and Redhat Xnio.
How can I fix CVE-2022-0084?
To fix CVE-2022-0084, update to the appropriate version of the affected software packages. Refer to the Red Hat Security Advisories for more information.
What is the Common Weakness Enumeration (CWE) for CVE-2022-0084?
The Common Weakness Enumeration (CWE) for CVE-2022-0084 is CWE-770.