First published: Thu May 16 2024(Updated: )
An update for Red Hat Build of Apache Camel 4.4 for Quarkus 3.8 update is now available (RHBQ 3.8.4.SP1).<br>The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products:<br><li> CVE-2024-29025 netty-codec-<a href="http:" target="_blank">http:</a> Allocation of Resources Without Limits or Throttling</li> <li> CVE-2024-28752 cxf-core: Apache CXF SSRF Vulnerability using the Aegis databinding</li> <li> CVE-2024-22371 camel-core: Exposure of sensitive data by crafting a malicious EventFactory</li>
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Quarkus |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2024:2834 is classified as important.
To resolve RHSA-2024:2834, update to Red Hat Build of Apache Camel 4.4 for Quarkus 3.8 to the version 3.8.4.SP1.
RHSA-2024:2834 affects Red Hat Integration - Camel Extensions for Quarkus.
RHSA-2024:2834 includes enhancements that improve the developer experience and enhance security and stability.
Yes, RHSA-2024:2834 is associated with CVE-2024-29025.