RHSA-2024:3550: Important: HawtIO 4.0.0 for Red Hat build of Apache Camel 4 Release and security update.
HawtIO 4.0.0 for Red Hat build of Apache Camel 4 GA Release is now available.<br>The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products.<br><li> spring-security: Broken Access Control in Spring Security With Direct Use of isFullyAuthenticated (TRIAGE CVE-2024-22234)</li> <li> nodejs-ip: arbitrary code execution via the isPublic() function (TRIAGE CVE-2023-42282)</li> <li> jose4j: denial of service via specially crafted JWE (TRIAGE CVE-2023-51775)</li> <li> netty-codec-<a href="http:" target="blank">http:</a> Allocation of Resources Without Limits or Throttling (TRIAGE CVE-2024-29025)</li> <li> follow-redirects: Possible credential leak (TRIAGE CVE-2024-28849)</li>
Other sources
Important: HawtIO 4.0.0 for Red Hat build of Apache Camel 4 Release and security update.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:3550?
The severity of RHSA-2024:3550 is classified as important.
How do I fix RHSA-2024:3550?
To fix RHSA-2024:3550, update to the latest version of the Red Hat Build of Apache Camel.
What vulnerabilities are addressed in RHSA-2024:3550?
RHSA-2024:3550 addresses multiple vulnerabilities affecting the spring-security component.
Is RHSA-2024:3550 applicable to all Red Hat users?
RHSA-2024:3550 is specifically applicable to users of the Red Hat Build of Apache Camel.
What enhancements are included in RHSA-2024:3550?
RHSA-2024:3550 includes enhancements that improve developer experience and enhance security and stability.