Important: Red Hat Build of Apache Camel 4.10.3 for Spring Boot release, security update.
Important: Red Hat Build of Apache Camel 4.8.5 for Spring Boot security update.
Important: Red Hat Build of Apache Camel 4.8.3 for Spring Boot security update.
Important: Red Hat Build of Apache Camel 4.8 for Spring Boot security update.
Critical: Red Hat Build of Apache Camel 4.4.4 for Spring Boot security update.
Critical: Red Hat Build of Apache Camel 4.4.3 for Spring Boot security update.
Important: Red Hat Build of Apache Camel 3.20.7 for Spring Boot security update.
Important: Red Hat Build of Apache Camel 4.4.2 for Spring Boot security update.
Important: Red Hat Build of Apache Camel 3.20.6 for Spring Boot security update.
Important: Red Hat Build of Apache Camel security update
Important: Red Hat Integration Camel for Spring Boot 4.0.3 release security update
Important: Red Hat Integration Camel for Spring Boot 3.20.4 release and security update
Important: Red Hat Integration Camel for Spring Boot 4.0.2 release security update
Important: Red Hat Integration Camel for Spring Boot 4.0.1 release security update
Moderate: Red Hat Integration Camel for Spring Boot 4.0.0 release and security update
Important: Red Hat Integration Camel for Spring Boot 3.20.2 release and security update
A security update for Camel for Spring Boot 3.18.3.2 is now available. The purpose of this text-only errata is to inform you about the security issues fixed in this release. spring-boot: Security Bypass With Wildcard Pattern Matching on Cloud Foundry (CVE-2023-20873) jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode (CVE-2021-46877) bouncycastle: potential blind LDAP injection attack using a self-signed certificate (CVE-2023-33201) snappy-java: Unchecked chunk length leads to DoS (CVE-2023-34455) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
This release of Camel for Spring Boot 3.18.3 serves as a replacement for Camel for Spring Boot 3.14.2 and includes bug fixes and enhancements, which are documented in the Release Notes document linked in the References.Security Fix(es): commons-text: apache-commons-text: variable interpolation (CVE-2022-42889) org.eclipse.milo-sdk-server: sdk-server: Denial of Service (CVE-2022-25897) reactor-netty-http: Log request headers in some cases of invalid HTTP requests (CVE-2022-31684) For more details about the security issues, including the impact, CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
This release of Camel for Spring Boot 3.14.5 serves as a replacement for Camel for Spring Boot 3.14.2 and includes bug fixes and enhancements, which are documented in the Release Notes document linked in the References.Security Fix(es): google-oauth-client: Token signature not verified (CVE-2021-22573) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.