Critical: Red Hat Build of Apache Camel 4.4.3 for Spring Boot security update.
Critical: Red Hat Build of Apache Camel 4.4.4 for Spring Boot security update.
Important: Red Hat Integration Camel for Spring Boot 4.0.3 release security update
Important: Red Hat Build of Apache Camel security update
Important: Red Hat Build of Apache Camel 3.20.6 for Spring Boot security update.
Important: Red Hat Build of Apache Camel 4.4.2 for Spring Boot security update.
Important: Red Hat Build of Apache Camel 3.20.7 for Spring Boot security update.
Important: Red Hat Build of Apache Camel 4.8 for Spring Boot security update.
Important: Red Hat Build of Apache Camel 4.8.3 for Spring Boot security update.
Important: Red Hat Build of Apache Camel 4.8.5 for Spring Boot security update.
Important: Red Hat Build of Apache Camel 4.10.3 for Spring Boot release, security update.
Important: Red Hat Integration Camel for Spring Boot 3.20.2 release and security update
A security update for Camel for Spring Boot 3.18.3.2 is now available. The purpose of this text-only errata is to inform you about the security issues fixed in this release. spring-boot: Security Bypass With Wildcard Pattern Matching on Cloud Foundry (CVE-2023-20873) jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode (CVE-2021-46877) bouncycastle: potential blind LDAP injection attack using a self-signed certificate (CVE-2023-33201) snappy-java: Unchecked chunk length leads to DoS (CVE-2023-34455) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Important: Red Hat Integration Camel for Spring Boot 4.0.1 release security update
Important: Red Hat Integration Camel for Spring Boot 4.0.2 release security update
Important: Red Hat Integration Camel for Spring Boot 3.20.4 release and security update
Moderate: Red Hat Integration Camel for Spring Boot 4.0.0 release and security update
This release of Camel for Spring Boot 3.14.5 serves as a replacement for Camel for Spring Boot 3.14.2 and includes bug fixes and enhancements, which are documented in the Release Notes document linked in the References.Security Fix(es): google-oauth-client: Token signature not verified (CVE-2021-22573) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
This release of Camel for Spring Boot 3.18.3 serves as a replacement for Camel for Spring Boot 3.14.2 and includes bug fixes and enhancements, which are documented in the Release Notes document linked in the References.Security Fix(es): commons-text: apache-commons-text: variable interpolation (CVE-2022-42889) org.eclipse.milo-sdk-server: sdk-server: Denial of Service (CVE-2022-25897) reactor-netty-http: Log request headers in some cases of invalid HTTP requests (CVE-2022-31684) For more details about the security issues, including the impact, CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.