Important: HawtIO 4.2.0 for Red Hat build of Apache Camel 4 Release and security update.
An update for Red Hat Build of Apache Camel 4.8 for Quarkus 3.15 update is now available (RHBQ 3.15.4.GA).The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products: quarkus-camel-bom: Potential DoS via stack exhaustion (CVE-2024-57699) com.redhat.quarkus.platform/quarkus-cxf-bom: SmallRye Fault Tolerance (CVE-2025-2240) com.redhat.quarkus.platform/quarkus-camel-bom: SmallRye Fault Tolerance (CVE-2025-2240)
Moderate: Red Hat Build of Apache Camel 4.8 for Quarkus 3.15 update is now available (RHBQ 3.15.3.SP2)
Important: Red Hat Build of Apache Camel 4.8 for Quarkus 3.15 update is now available (RHBQ 3.15.3.SP1)
An update for Red Hat Build of Apache Camel 4.8 for Quarkus 3.15 update is now available (RHBQ 3.15.3.GA).<br>The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products:<br><li> com.redhat.quarkus.platform/quarkus-cxf-bom: Quarkus HTTP Cookie Smuggling (CVE-2024-12397)</li> <li> com.redhat.quarkus.platform/quarkus-camel-bom: Quarkus HTTP Cookie Smuggling (CVE-2024-12397)</li>
HawtIO 4.1.0 for Red Hat build of Apache Camel 4 GA Release is now available.The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products. serve-static: Improper Sanitization in serve-static (CVE-2024-43800) send: Code Execution Vulnerability in Send Library (CVE-2024-43799) org.springframework/spring-webmvc: Path Traversal Vulnerability in Spring Applications Using RouterFunctions and FileSystemResource (CVE-2024-38816) org.eclipse.jetty/jetty-server: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks (CVE-2024-8184) quarkus-core: Leak of local configuration properties into Quarkus applications (CVE-2024-2700) braces: fails to limit the number of characters it can handle (CVE-2024-4068) undertow: Improper State Management in Proxy Protocol parsing causes information leakage (CVE-2024-7885) path-to-regexp: Backtracking regular expressions cause ReDoS (CVE-2024-45296) express: Improper Input Handling in Express Redirects (CVE-2024-43796)
An update for Red Hat Build of Apache Camel 4.8 for Quarkus 3.15 update is now available (RHBQ 3.15.2.GA).<br>The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products:<br><li> CVE-2024-31141 org.apache.kafka/kafka-clients: privilege escalation to filesystem read-access via automatic ConfigProvider</li>
An update for Red Hat Build of Apache Camel 4.4 for Quarkus 3.8 update is now available (RHBQ 3.8.6.SP2).<br>The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products:<br><li> [Minor Incident] CVE-2024-51132 ca.uhn.hapi.fhir/org.hl7.fhir.dstu3: FHIR arbitrary code execution via specially-crafted request</li> <li> [Minor Incident] CVE-2024-51132 ca.uhn.hapi.fhir/org.hl7.fhir.dstu2: FHIR arbitrary code execution via specially-crafted request</li> <li> [Minor Incident] CVE-2024-51132 ca.uhn.hapi.fhir/org.hl7.fhir.r5: FHIR arbitrary code execution via specially-crafted request</li> <li> [Minor Incident] CVE-2024-51132 ca.uhn.hapi.fhir/org.hl7.fhir.r4: FHIR arbitrary code execution via specially-crafted request</li> <li> [Minor Incident] CVE-2024-51132 ca.uhn.hapi.fhir/org.hl7.fhir.dstu2016may: FHIR arbitrary code execution via specially-crafted request</li> <li> [Minor Incident] CVE-2024-51132 ca.uhn.hapi.fhir-org.hl7.fhir.utilities: FHIR arbitrary code execution via specially-crafted request</li> <li> CVE-2024-9621 io.quarkiverse.cxf/quarkus-cxf: Quarkus CXF may log user password and secret to application log</li>
An update for Red Hat Build of Apache Camel 4.4 for Quarkus 3.8 update is now available (RHBQ 3.8.6.SP1).<br>The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products:<br><li> CVE-2024-47561 org.apache.avro/avro: Schema parsing may trigger Remote Code Execution (RCE)</li> <li> CVE-2024-7254 com.google.protobuf/protobuf-java: StackOverflow vulnerability in Protocol Buffers</li>
An update for Red Hat Build of Apache Camel 4.4 for Quarkus 3.8 update is now available (RHBQ 3.8.6.GA).<br>The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products:<br><li> CVE-2024-45294 ca.uhn.hapi.fhir/org.hl7.fhir.utilities: XXE vulnerability in XSLT transforms in </li> <li> CVE-2024-45294 ca.uhn.hapi.fhir/org.hl7.fhir.r5: XXE vulnerability in XSLT transforms in </li> <li> CVE-2024-45294 ca.uhn.hapi.fhir/org.hl7.fhir.r4: XXE vulnerability in XSLT transforms in </li> <li> CVE-2024-45294 ca.uhn.hapi.fhir/org.hl7.fhir.dstu3: XXE vulnerability in XSLT transforms in </li> <li> CVE-2024-45294 ca.uhn.hapi.fhir/org.hl7.fhir.dstu2016may: XXE vulnerability in XSLT transforms in </li> <li> CVE-2024-8391 io.vertx/vertx-grpc-server: Vertx gRPC server does not limit the maximum message size</li> <li> CVE-2024-8391 io.vertx/vertx-grpc-client: Vertx gRPC server does not limit the maximum message size</li> <li> CVE-2024-32007 org.apache.cxf/cxf-rt-rs-security-jose: apache: cxf: org.apache.cxf:cxf-rt-rs-security-jose: Denial of Service vulnerability in JOSE</li> <li> CVE-2024-41172 org.apache.cxf/cxf-rt-transports-<a href="http:" target="blank">http:</a> unrestricted memory consumption in CXF HTTP clients</li> <li> CVE-2024-35255 com.azure/azure-identity: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity</li>
HawtIO 4.0.0 for Red Hat build of Apache Camel 4 GA Release is now available.<br>The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products.<br><li> spring-security: Broken Access Control in Spring Security With Direct Use of isFullyAuthenticated (TRIAGE CVE-2024-22234)</li> <li> nodejs-ip: arbitrary code execution via the isPublic() function (TRIAGE CVE-2023-42282)</li> <li> jose4j: denial of service via specially crafted JWE (TRIAGE CVE-2023-51775)</li> <li> netty-codec-<a href="http:" target="blank">http:</a> Allocation of Resources Without Limits or Throttling (TRIAGE CVE-2024-29025)</li> <li> follow-redirects: Possible credential leak (TRIAGE CVE-2024-28849)</li>
Server-Side Template Injection and arbitrary file disclosure on Camel templating components.
Reference: https://camel.apache.org/security/CVE-2020-11994.html
A flaw was found in camel. Camel's templating components are suseptable to Server-Side Template Injection and arbitrary file disclosure. The highest threat from this vulnerability is to data confidentiality.
A flaw was found in camel up to versions 2.25.1 and 3.x. Apache Camel RabbitMQ enables java deserialization, by default, without any means of disabling which can lead to arbitrary code being executed. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.
Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected.
Apache Camel's camel-castor component is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
Versions Affected: Camel 2.19.0 to 2.19.3 and Camel 2.20.0 The unsupported Camel 2.x (2.18 and earlier) versions may be also affected.
References:
https://camel.apache.org/security-advisories.data/CVE-2017-12634.txt.asc https://issues.apache.org/jira/browse/CAMEL-11929
Apache Camel's camel-hessian component is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
Versions Affected: Camel 2.19.0 to 2.19.3 and Camel 2.20.0 The unsupported Camel 2.x (2.18 and earlier) versions may be also affected.
References:
https://camel.apache.org/security-advisories.data/CVE-2017-12633.txt.asc https://issues.apache.org/jira/browse/CAMEL-11923
Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.
The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.
XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an external entity in an SAXSource.
Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) GenericFile object in an XPath query.
It was found that the Apache Camel XSLT component allowed XSL stylesheets to perform calls to external Java methods. A remote attacker able to submit messages to an xslt: Camel route could use this flaw to perform arbitrary remote code execution in the context of the Camel server process.
It was found that the Apache Camel XSLT component would resolve entities in XML messages when transforming them using an xslt: route. A remote attacker able to submit messages to an xslt: Camel route could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.
Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.