RHSA-2023:3641: Important: Red Hat Integration Camel for Spring Boot 3.18.3 Patch 2 release
This release of Camel for Spring Boot 3.18.3.P2 serves as a replacement for Camel for Spring Boot 3.18.3.P1 and includes bug fixes and enhancements, which are documented in the Release Notes linked in the References. The purpose of this text-only errata is to inform you about the security issues fixed.<br><li> spring-boot: Spring Boot Welcome Page DoS Vulnerability (CVE-2023-20883)</li> <li> woodstox-core: woodstox to serialise XML data was vulnerable to Denial of Service attacks (CVE-2022-40152)</li> <li> xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks (CVE-2022-40156)</li> <li> dev-java-snakeyaml: dev-java/snakeyaml: DoS via stack overflow (CVE-2022-41854)</li> <li> snakeyaml: Denial of Service due to missing nested depth limitation for collections (CVE-2022-25857)</li> <li> sshd-common: mina-sshd: Java unsafe deserialization vulnerability (CVE-2022-45047)</li> <li> jettison: Uncontrolled Recursion in JSONArray (CVE-2023-1436)</li> <li> json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) (CVE-2023-1370)</li> <li> jackson-databind: use of deeply nested arrays (CVE-2022-42004)</li> <li> jackson-databind: deep wrapper array nesting wrt UNWRAPSINGLEVALUEARRAYS (CVE-2022-42003)</li> <li> snakeyaml: Uncaught exception in org.yaml.snakeyaml.composer.Composer.composeSequenceNode (CVE-2022-38749)</li> <li> snakeyaml: Uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObject (CVE-2022-38750)</li> <li> snakeyaml: Uncaught exception in java.base/java.util.regex.Pattern.match (CVE-2022-38751)</li> <li> snakeyaml: Uncaught exception in java.base/java.util.ArrayList.hashCode (CVE-2022-38752)</li> <li> snakeyaml: Denial of Service due to missing nested depth limitation for collections (CVE-2022-25857)</li> <li> CXF: Apache CXF: directory listing / code exfiltration (CVE-2022-46363)</li> <li> CXF: Apache CXF: SSRF Vulnerability (CVE-2022-46364)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:3641?
The severity of RHSA-2023:3641 is not explicitly stated in the available information.
How do I fix RHSA-2023:3641?
To fix RHSA-2023:3641, users should update to Camel for Spring Boot 3.18.3.P2 as recommended in the release notes.
What issues does RHSA-2023:3641 address?
RHSA-2023:3641 addresses bug fixes and enhancements over the previous version, Camel for Spring Boot 3.18.3.P1.
Which software versions are affected by RHSA-2023:3641?
The affected software for RHSA-2023:3641 is specifically Camel for Spring Boot versions prior to 3.18.3.P2.
Is there a workaround for RHSA-2023:3641?
No specific workarounds for RHSA-2023:3641 are provided; the recommendation is to update to the latest version.