First published: Tue Oct 25 2022(Updated: )
This release of Camel for Spring Boot 3.14.5 serves as a replacement for Camel for Spring Boot 3.14.2 and includes bug fixes and enhancements, which are documented in the Release Notes document linked in the References.<br>Security Fix(es):<br><li> google-oauth-client: Token signature not verified (CVE-2021-22573)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Integration - Camel for Spring Boot | <3.14.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:7177 is classified as important.
To fix RHSA-2022:7177, you should upgrade to Red Hat Camel for Spring Boot version 3.14.5 or later.
RHSA-2022:7177 addresses vulnerabilities related to the google-oauth-client's token signature validation.
Red Hat Camel for Spring Boot versions up to and including 3.14.2 are affected by RHSA-2022:7177.
Yes, the release notes for RHSA-2022:7177 include detailed information about bug fixes and enhancements.