First published: Wed Jun 21 2023(Updated: )
This release of Camel for Spring Boot 3.20.1.P1 serves as a replacement for Camel for Spring Boot 3.20.1 and includes bug fixes and enhancements, which are documented in the Release Notes linked in the References. The purpose of this text-only errata is to inform you about the security issues fixed.<br>Security Fix(es):<br><li> vertx-web: StaticHandler disclosure of classpath resources on Windows when mounted on a wildcard route (CVE-2023-24815)</li> <li> spring-boot: Spring Boot Welcome Page DoS Vulnerability (CVE-2023-20883)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
=3.20.1.P1 | ||
<3.20.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2023:3740 is classified as important.
To fix RHSA-2023:3740, you should upgrade to Camel for Spring Boot 3.20.1.P1.
The purpose of RHSA-2023:3740 is to address bug fixes and enhancements in the Camel for Spring Boot framework.
RHSA-2023:3740 is applicable to systems using Camel for Spring Boot version 3.20.1.
Yes, RHSA-2023:3740 addresses security vulnerabilities documented in the release notes.