RHSA-2024:0789: Important: Red Hat Build of Apache Camel 4.0 for Quarkus 3.2 release (RHBQ 3.2.10.Final)
An update for Red Hat Build of Apache Camel 4.0 for Quarkus 3.2 is now available (updates to RHBQ 3.2.10.Final). The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products.Security Fix(es): parsson: Denial of Service due to large number parsing (CVE-2023-4043) santuario: Private Key disclosure in debug-log output (CVE-2023-44483) ssh: Prefix truncation attack on Binary Packet Protocol (BPP) (CVE-2023-48795) json-path: stack-based buffer overflow in Criteria.parse method (CVE-2023-51074) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Important: Red Hat Build of Apache Camel 4.0 for Quarkus 3.2 release (RHBQ 3.2.10.Final)
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0789?
The severity of RHSA-2024:0789 is considered to be critical due to the potential impact on security and stability.
How do I fix RHSA-2024:0789?
To fix RHSA-2024:0789, update your Red Hat Build of Apache Camel for Quarkus to the latest version provided in the advisory.
What products are affected by RHSA-2024:0789?
RHSA-2024:0789 affects the Red Hat Integration - Camel Extensions for Quarkus.
What enhancements are included in RHSA-2024:0789?
RHSA-2024:0789 includes enhancements that improve the developer experience along with ensuring security and stability for products.
Is there a workaround for RHSA-2024:0789?
There are no specific workarounds provided for RHSA-2024:0789, and applying the update is recommended.