Red Hat Security Advisory: Red Hat Integration Camel Extensions for Quarkus 2.2.1 security update
🔗 CVE IDs covered (14)
📋 Description
CVE-2020-8908 — guava: local information disclosure via temporary directory created with unsafe permissions CVE-2020-15522 — bouncycastle: Timing issue within the EC math library CVE-2021-2471 — mysql-connector-java: unauthorized access to critical CVE-2021-4178 — kubernetes-client: Insecure deserialization in unmarshalYaml method CVE-2021-22569 — protobuf-java: potential DoS in the parsing procedure for binary data CVE-2021-26291 — maven: Block repositories using http by default CVE-2021-28168 — jersey: Local information disclosure via system temporary directory CVE-2021-28170 — jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate CVE-2021-30129 — mina-sshd-core: Memory leak denial of service in Apache Mina SSHD Server CVE-2021-37136 — netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data CVE-2021-37137 — netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary way CVE-2021-40690 — xml-security: XPath Transform abuse allows for information disclosure CVE-2021-41269 — cron-utils: template Injection leading to unauthenticated Remote Code Execution CVE-2021-42392 — h2: Remote Code Execution in Console
🔗 References (19)
- selfhttps://access.redhat.com/errata/RHSA-2022:1013
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2022-Q2
- externalhttps://access.redhat.com/documentation/en-us/red_hat_integration/2022.q2
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1906919
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1953024
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1955739
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1962879
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1965497
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1981527
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2004133
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2004135
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011190
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2020583
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2024632
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2034388
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2039403
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2039903
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_1013.json