First published: Thu Jul 11 2024(Updated: )
An update for Red Hat Build of Apache Camel 4.4 for Quarkus 3.8 update is now available (RHBQ 3.8.5.GA).<br>The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products:<br><li> CVE-2024-29857 org.bouncycastle:bcprov-jdk18on: org.bouncycastle: Importing an EC certificate with crafted F2m parameters may lead to Denial of Service</li> <li> CVE-2024-30172 org.bouncycastle:bcprov-jdk18on: Infinite loop in ED25519 verification in the ScalarUtil class</li> <li> CVE-2024-30171 org.bouncycastle-bcprov-jdk18on: bc-java: BouncyCastle vulnerable to a timing variant of Bleichenbacher (Marvin Attack)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Quarkus |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2024:4505 is classified as moderate.
You can fix RHSA-2024:4505 by updating to Red Hat Build of Apache Camel 4.4 for Quarkus 3.8.5.GA.
RHSA-2024:4505 affects Red Hat Integration - Camel Extensions for Quarkus.
RHSA-2024:4505 includes enhancements that improve the developer experience and ensure the security and stability of your products.
Yes, RHSA-2024:4505 comes with a release note detailing the updates and enhancements available in the new version.