RHSA-2023:0888: Moderate: Red Hat Integration Camel Extension For Quarkus 2.13.2-1 security update
A security update for 2.13.2-1 is now available. The purpose of this text-only errata is to inform you about the security issues fixed.Security Fix(es): codec-haproxy: HAProxyMessageDecoder Stack Exhaustion DoS (CVE-2022-41881) postgresql-jdbc: PreparedStatement.setText(int, InputStream) will create a temporary file if the InputStream is larger than 2k (CVE-2022-41946) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:0888?
The severity of RHSA-2023:0888 is classified as moderate.
What vulnerabilities are addressed in RHSA-2023:0888?
RHSA-2023:0888 addresses vulnerabilities including HAProxyMessageDecoder Stack Exhaustion DoS (CVE-2022-41881).
How do I fix RHSA-2023:0888?
To fix RHSA-2023:0888, you need to update the affected software to the version 2.13.2-1 or later.
What is the impact of the vulnerabilities fixed in RHSA-2023:0888?
The vulnerabilities fixed in RHSA-2023:0888 can lead to denial of service conditions affecting application performance.
Who is affected by RHSA-2023:0888?
RHSA-2023:0888 affects users of the affected software that relies on HAProxy and PostgreSQL JDBC integrations.