RHSA-2024:11023: Important: HawtIO 4.1.0 for Red Hat build of Apache Camel 4 Release and security update.
HawtIO 4.1.0 for Red Hat build of Apache Camel 4 GA Release is now available.The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products. serve-static: Improper Sanitization in serve-static (CVE-2024-43800) send: Code Execution Vulnerability in Send Library (CVE-2024-43799) org.springframework/spring-webmvc: Path Traversal Vulnerability in Spring Applications Using RouterFunctions and FileSystemResource (CVE-2024-38816) org.eclipse.jetty/jetty-server: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks (CVE-2024-8184) quarkus-core: Leak of local configuration properties into Quarkus applications (CVE-2024-2700) braces: fails to limit the number of characters it can handle (CVE-2024-4068) undertow: Improper State Management in Proxy Protocol parsing causes information leakage (CVE-2024-7885) path-to-regexp: Backtracking regular expressions cause ReDoS (CVE-2024-45296) express: Improper Input Handling in Express Redirects (CVE-2024-43796)
Other sources
Important: HawtIO 4.1.0 for Red Hat build of Apache Camel 4 Release and security update.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:11023?
The severity level of RHSA-2024:11023 is determined by the specific vulnerabilities addressed, which typically include potential security and stability risks.
How do I fix RHSA-2024:11023?
To fix RHSA-2024:11023, you should update your Red Hat Build of Apache Camel to the latest version provided in the advisory.
What vulnerabilities are addressed in RHSA-2024:11023?
RHSA-2024:11023 addresses vulnerabilities that may impact the security and performance of the Red Hat Build of Apache Camel.
Is RHSA-2024:11023 critical for all users?
The criticality of RHSA-2024:11023 for users depends on their specific deployment and usage of Red Hat Build of Apache Camel.
What enhancements are included in RHSA-2024:11023?
RHSA-2024:11023 includes enhancements aimed at improving the developer experience alongside addressing security and stability issues.