RHSA-2023:5441: Moderate: Red Hat Integration Camel for Spring Boot 4.0.0 release and security update
Moderate: Red Hat Integration Camel for Spring Boot 4.0.0 release and security update
Other sources
Red Hat Integration Camel for Spring Boot 4.0.0 is now available. The purpose of this text-only errata is to inform you about the security issues fixed. batik: Server-Side Request Forgery vulnerability (CVE-2022-44729) batik: Server-Side Request Forgery vulnerability (CVE-2022-44730) apache-ivy: XML External Entity vulnerability (CVE-2022-46751) jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter() (CVE-2023-26048) jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies (CVE-2023-26049) apache-johnzon: Prevent inefficient internal conversion from BigDecimal at large scale (CVE-2023-33008) netty: io.netty:netty-handler: SniHandler 16MB allocation (CVE-2023-34462) jetty-http: jetty: Improper validation of HTTP/1 content-length (CVE-2023-40167) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:5441?
The severity of RHSA-2023:5441 is medium.
What software is affected by RHSA-2023:5441?
Red Hat Integration Camel for Spring Boot is affected by RHSA-2023:5441.
Are there any reference links for RHSA-2023:5441?
Yes, you can find reference links for RHSA-2023:5441 at the following locations: - [Bugzilla - 2216888](https://bugzilla.redhat.com/show_bug.cgi?id=2216888) - [Bugzilla - 2221135](https://bugzilla.redhat.com/show_bug.cgi?id=2221135) - [Bugzilla - 2233112](https://bugzilla.redhat.com/show_bug.cgi?id=2233112)