Where
-Infinity
0
Severity
7

Important: HawtIO 4.2.0 for Red Hat build of Apache Camel 4 Release and security update.

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

An update for Red Hat Build of Apache Camel 4.8 for Quarkus 3.15 update is now available (RHBQ 3.15.4.GA).The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products: quarkus-camel-bom: Potential DoS via stack exhaustion (CVE-2024-57699) com.redhat.quarkus.platform/quarkus-cxf-bom: SmallRye Fault Tolerance (CVE-2025-2240) com.redhat.quarkus.platform/quarkus-camel-bom: SmallRye Fault Tolerance (CVE-2025-2240)

1 / 2
Source: Red Hat

Remedy

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.<br>The References section of this erratum contains a download link (you must log in to download the update).
First published (updated )
Severity
4

Moderate: Red Hat Build of Apache Camel 4.8 for Quarkus 3.15 update is now available (RHBQ 3.15.3.SP2)

Remedy

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.<br>The References section of this erratum contains a download link (you must log in to download the update).
First published (updated )
Severity
7

Important: Red Hat Build of Apache Camel 4.8 for Quarkus 3.15 update is now available (RHBQ 3.15.3.SP1)

Remedy

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.<br>The References section of this erratum contains a download link (you must log in to download the update).
First published (updated )
Severity
4

An update for Red Hat Build of Apache Camel 4.8 for Quarkus 3.15 update is now available (RHBQ 3.15.3.GA).<br>The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products:<br><li> com.redhat.quarkus.platform/quarkus-cxf-bom: Quarkus HTTP Cookie Smuggling (CVE-2024-12397)</li> <li> com.redhat.quarkus.platform/quarkus-camel-bom: Quarkus HTTP Cookie Smuggling (CVE-2024-12397)</li>

1 / 2
Source: Red Hat

Remedy

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.<br>The References section of this erratum contains a download link (you must log in to download the update).
First published (updated )
Severity
7
Path Traversal

HawtIO 4.1.0 for Red Hat build of Apache Camel 4 GA Release is now available.The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products. serve-static: Improper Sanitization in serve-static (CVE-2024-43800) send: Code Execution Vulnerability in Send Library (CVE-2024-43799) org.springframework/spring-webmvc: Path Traversal Vulnerability in Spring Applications Using RouterFunctions and FileSystemResource (CVE-2024-38816) org.eclipse.jetty/jetty-server: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks (CVE-2024-8184) quarkus-core: Leak of local configuration properties into Quarkus applications (CVE-2024-2700) braces: fails to limit the number of characters it can handle (CVE-2024-4068) undertow: Improper State Management in Proxy Protocol parsing causes information leakage (CVE-2024-7885) path-to-regexp: Backtracking regular expressions cause ReDoS (CVE-2024-45296) express: Improper Input Handling in Express Redirects (CVE-2024-43796)

1 / 2
Source: Red Hat

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
4

An update for Red Hat Build of Apache Camel 4.8 for Quarkus 3.15 update is now available (RHBQ 3.15.2.GA).<br>The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products:<br><li> CVE-2024-31141 org.apache.kafka/kafka-clients: privilege escalation to filesystem read-access via automatic ConfigProvider</li>

1 / 2
Source: Red Hat

Remedy

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.<br>The References section of this erratum contains a download link (you must log in to download the update).
First published (updated )
Severity
9

An update for Red Hat Build of Apache Camel 4.4 for Quarkus 3.8 update is now available (RHBQ 3.8.6.SP2).<br>The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products:<br><li> [Minor Incident] CVE-2024-51132 ca.uhn.hapi.fhir/org.hl7.fhir.dstu3: FHIR arbitrary code execution via specially-crafted request</li> <li> [Minor Incident] CVE-2024-51132 ca.uhn.hapi.fhir/org.hl7.fhir.dstu2: FHIR arbitrary code execution via specially-crafted request</li> <li> [Minor Incident] CVE-2024-51132 ca.uhn.hapi.fhir/org.hl7.fhir.r5: FHIR arbitrary code execution via specially-crafted request</li> <li> [Minor Incident] CVE-2024-51132 ca.uhn.hapi.fhir/org.hl7.fhir.r4: FHIR arbitrary code execution via specially-crafted request</li> <li> [Minor Incident] CVE-2024-51132 ca.uhn.hapi.fhir/org.hl7.fhir.dstu2016may: FHIR arbitrary code execution via specially-crafted request</li> <li> [Minor Incident] CVE-2024-51132 ca.uhn.hapi.fhir-org.hl7.fhir.utilities: FHIR arbitrary code execution via specially-crafted request</li> <li> CVE-2024-9621 io.quarkiverse.cxf/quarkus-cxf: Quarkus CXF may log user password and secret to application log</li>

1 / 2
Source: Red Hat

Remedy

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.<br>The References section of this erratum contains a download link (you must log in to download the update).
First published (updated )
Severity
9

An update for Red Hat Build of Apache Camel 4.4 for Quarkus 3.8 update is now available (RHBQ 3.8.6.SP1).<br>The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products:<br><li> CVE-2024-47561 org.apache.avro/avro: Schema parsing may trigger Remote Code Execution (RCE)</li> <li> CVE-2024-7254 com.google.protobuf/protobuf-java: StackOverflow vulnerability in Protocol Buffers</li>

1 / 2
Source: Red Hat

Remedy

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.<br>The References section of this erratum contains a download link (you must log in to download the update).
First published (updated )
Severity
7

An update for Red Hat Build of Apache Camel 4.4 for Quarkus 3.8 update is now available (RHBQ 3.8.6.GA).<br>The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products:<br><li> CVE-2024-45294 ca.uhn.hapi.fhir/org.hl7.fhir.utilities: XXE vulnerability in XSLT transforms in </li> <li> CVE-2024-45294 ca.uhn.hapi.fhir/org.hl7.fhir.r5: XXE vulnerability in XSLT transforms in </li> <li> CVE-2024-45294 ca.uhn.hapi.fhir/org.hl7.fhir.r4: XXE vulnerability in XSLT transforms in </li> <li> CVE-2024-45294 ca.uhn.hapi.fhir/org.hl7.fhir.dstu3: XXE vulnerability in XSLT transforms in </li> <li> CVE-2024-45294 ca.uhn.hapi.fhir/org.hl7.fhir.dstu2016may: XXE vulnerability in XSLT transforms in </li> <li> CVE-2024-8391 io.vertx/vertx-grpc-server: Vertx gRPC server does not limit the maximum message size</li> <li> CVE-2024-8391 io.vertx/vertx-grpc-client: Vertx gRPC server does not limit the maximum message size</li> <li> CVE-2024-32007 org.apache.cxf/cxf-rt-rs-security-jose: apache: cxf: org.apache.cxf:cxf-rt-rs-security-jose: Denial of Service vulnerability in JOSE</li> <li> CVE-2024-41172 org.apache.cxf/cxf-rt-transports-<a href="http:" target="blank">http:</a> unrestricted memory consumption in CXF HTTP clients</li> <li> CVE-2024-35255 com.azure/azure-identity: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity</li>

1 / 2
Source: Red Hat

Remedy

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.<br>The References section of this erratum contains a download link (you must log in to download the update).
First published (updated )
Severity
7

HawtIO 4.0.0 for Red Hat build of Apache Camel 4 GA Release is now available.<br>The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products.<br><li> spring-security: Broken Access Control in Spring Security With Direct Use of isFullyAuthenticated (TRIAGE CVE-2024-22234)</li> <li> nodejs-ip: arbitrary code execution via the isPublic() function (TRIAGE CVE-2023-42282)</li> <li> jose4j: denial of service via specially crafted JWE (TRIAGE CVE-2023-51775)</li> <li> netty-codec-<a href="http:" target="blank">http:</a> Allocation of Resources Without Limits or Throttling (TRIAGE CVE-2024-29025)</li> <li> follow-redirects: Possible credential leak (TRIAGE CVE-2024-28849)</li>

1 / 2
Source: Red Hat

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Server-Side Template Injection and arbitrary file disclosure on Camel templating components.

Reference: https://camel.apache.org/security/CVE-2020-11994.html

First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

A flaw was found in camel. Camel's templating components are suseptable to Server-Side Template Injection and arbitrary file disclosure. The highest threat from this vulnerability is to data confidentiality.

1 / 3
First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A flaw was found in camel up to versions 2.25.1 and 3.x. Apache Camel RabbitMQ enables java deserialization, by default, without any means of disabling which can lead to arbitrary code being executed. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

1 / 3
First published (updated )
Severity
7.5
XEE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.

First published (updated )
Severity
7.5
Path Traversal
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected.

First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Apache Camel's camel-castor component is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.

Versions Affected: Camel 2.19.0 to 2.19.3 and Camel 2.20.0 The unsupported Camel 2.x (2.18 and earlier) versions may be also affected.

References:

https://camel.apache.org/security-advisories.data/CVE-2017-12634.txt.asc https://issues.apache.org/jira/browse/CAMEL-11929

1 / 2
Source: Red Hat
First published (updated )
Severity
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Apache Camel's camel-hessian component is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.

Versions Affected: Camel 2.19.0 to 2.19.3 and Camel 2.20.0 The unsupported Camel 2.x (2.18 and earlier) versions may be also affected.

References:

https://camel.apache.org/security-advisories.data/CVE-2017-12633.txt.asc https://issues.apache.org/jira/browse/CAMEL-11923

1 / 3
Source: Red Hat
First published (updated )
Severity
8.1
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.

First published (updated )
Severity
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.

First published (updated )
Severity
5
XEE
AV:N/AC:L/Au:N/C:P/I:N/A:N

XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an external entity in an SAXSource.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:P/I:N/A:N

Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) GenericFile object in an XPath query.

First published (updated )
Severity
7

It was found that the Apache Camel XSLT component allowed XSL stylesheets to perform calls to external Java methods. A remote attacker able to submit messages to an xslt: Camel route could use this flaw to perform arbitrary remote code execution in the context of the Camel server process.

First published (updated )
Severity
4

It was found that the Apache Camel XSLT component would resolve entities in XML messages when transforming them using an xslt: route. A remote attacker able to submit messages to an xslt: Camel route could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.

First published (updated )
Severity
6.8
Code Injection
AV:N/AC:M/Au:N/C:P/I:P/A:P

Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203