Lucene search

K
redhatRedHatRHSA-2022:0223
HistoryJan 20, 2022 - 6:51 p.m.

(RHSA-2022:0223) Moderate: Red Hat Integration Camel-K 1.6.3 release and security update

2022-01-2018:51:49
access.redhat.com
42

0.976 High

EPSS

Percentile

100.0%

A minor version update (from 1.6.2 to 1.6.3) is now available for Red Hat Camel K that includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.

Security Fix(es):

  • log4j-core: remote code execution via JDBC Appender (CVE-2021-44832)

  • log4j-core: DoS in log4j 2.x with thread context message pattern and context lookup pattern (incomplete fix for CVE-2021-44228) (CVE-2021-45046)

  • log4j-core: DoS in log4j 2.x with Thread Context Map (MDC) input data contains a recursive lookup and context lookup pattern (CVE-2021-45105)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.