RHSA-2022:1013MediumCVSS 9.8

Red Hat Security Advisory: Red Hat Integration Camel Extensions for Quarkus 2.2.1 security update

Published
March 22, 2022
Last Modified
July 16, 2026

🔗 CVE IDs covered (14)

📋 Description

CVE-2020-8908 — guava: local information disclosure via temporary directory created with unsafe permissions CVE-2020-15522 — bouncycastle: Timing issue within the EC math library CVE-2021-2471 — mysql-connector-java: unauthorized access to critical CVE-2021-4178 — kubernetes-client: Insecure deserialization in unmarshalYaml method CVE-2021-22569 — protobuf-java: potential DoS in the parsing procedure for binary data CVE-2021-26291 — maven: Block repositories using http by default CVE-2021-28168 — jersey: Local information disclosure via system temporary directory CVE-2021-28170 — jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate CVE-2021-30129 — mina-sshd-core: Memory leak denial of service in Apache Mina SSHD Server CVE-2021-37136 — netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data CVE-2021-37137 — netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary way CVE-2021-40690 — xml-security: XPath Transform abuse allows for information disclosure CVE-2021-41269 — cron-utils: template Injection leading to unauthenticated Remote Code Execution CVE-2021-42392 — h2: Remote Code Execution in Console

🔗 References (19)