Important: Red Hat Integration Camel K 1.10.10 release and security update.
Camel K 1.10.9 is now available.The purpose of this text-only errata is to inform you about the security issues fixed.Security Fix(es): libsoup: buffer overflow via UTF-8 conversion in soupheaderparseparamliststrict (CVE-2024-52531) JDK: Enhance array handling (Oracle CPU 2025-01) (CVE-2025-21502) bzip2: bzip2: Data integrity error when decompressing (with data integrity tests fail). (CVE-2019-12900) graalvm: Unauthorized Read Access (CVE-2024-20954) graalvm: unauthorized ability to cause a partial denial of service (CVE-2024-21098) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE important page(s) listed in the References section.
Camel K 1.10.8 is now available.<br>The purpose of this text-only errata is to inform you about the security issues fixed.<br>Security Fix(es):<br><li> cxf-core: Apache CXF SSRF Vulnerability using the Aegis databinding (CVE-2024-28752)</li> <li> org.apache.avro/avro: Schema parsing may trigger Remote Code Execution (CVE-2024-47561)</li> <li> org.apache.camel-camel-cassandraql: : Apache Camel-CassandraQL: Unsafe Deserialization from CassandraAggregationRepository (CVE-2024-23114)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE important page(s) listed in the References section.
Important: Red Hat Integration Camel K 1.10.5 release and security update
A security update for Camel K 1.10.4 is now available.The purpose of this text-only errata is to inform you about the security issues fixed.Security Fix(es): HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487) A Red Hat Security Bulletin which addresses further details about the Rapid Reset flaw is available in the References section.For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
A security update for Camel K 1.10.2 is now available.The purpose of this text-only errata is to inform you about the security issues fixed.Security Fix(es): quarkus-vertx-http: quarkus: HTTP security policy bypass(CVE-2023-4853) See the Red Hat Security Bulletin in the References section for more detail about CVE-2023-4853.For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
A minor version update is now available for Red Hat Camel K that includes CVE fixes in the base images. Details are linked in the References section.Security Fix(es): jetty: requests to the ConcatServlet and WelcomeFilter are able to access protected resources within the WEB-INF directory (CVE-2021-28169) tika-core: incomplete fix for CVE-2022-30126 (CVE-2022-30973) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.