RHSA-2024:8339: Important: Red Hat Integration Camel K 1.10.8 release and security update.
Camel K 1.10.8 is now available.<br>The purpose of this text-only errata is to inform you about the security issues fixed.<br>Security Fix(es):<br><li> cxf-core: Apache CXF SSRF Vulnerability using the Aegis databinding (CVE-2024-28752)</li> <li> org.apache.avro/avro: Schema parsing may trigger Remote Code Execution (CVE-2024-47561)</li> <li> org.apache.camel-camel-cassandraql: : Apache Camel-CassandraQL: Unsafe Deserialization from CassandraAggregationRepository (CVE-2024-23114)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE important page(s) listed in the References section.
Other sources
Important: Red Hat Integration Camel K 1.10.8 release and security update.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What security vulnerabilities are addressed in RHSA-2024:8339?
RHSA-2024:8339 addresses an Apache CXF SSRF Vulnerability using the Aegis databinding (CVE-2024-28752) among other issues.
What is the severity of RHSA-2024:8339?
The severity of RHSA-2024:8339 is classified based on the vulnerabilities it addresses, which may vary depending on potential impact.
How do I fix the vulnerabilities outlined in RHSA-2024:8339?
To fix the vulnerabilities in RHSA-2024:8339, you should upgrade to the latest version of Red Hat Integration - Camel K as recommended in the advisory.
Which software versions are affected by RHSA-2024:8339?
RHSA-2024:8339 affects the Red Hat Integration - Camel K version 1.10.8.
Is there a workaround for the vulnerabilities in RHSA-2024:8339?
There are no official workarounds mentioned specifically for the vulnerabilities in RHSA-2024:8339, so updating is the recommended action.