Lucene search

K
redhatRedHatRHSA-2022:8902
HistoryDec 08, 2022 - 1:23 p.m.

(RHSA-2022:8902) Moderate: Red Hat Camel for Spring Boot 3.18.3 release and security update

2022-12-0813:23:48
access.redhat.com
29
red hat camel
spring boot 3.18.3
security update
commons-text
apache-commons-text
org.eclipse.milo-sdk-server
reactor-netty-http
cve-2022-42889
cve-2022-25897
cve-2022-31684

0.972 High

EPSS

Percentile

99.8%

This release of Camel for Spring Boot 3.18.3 serves as a replacement for Camel for Spring Boot 3.14.2 and includes bug fixes and enhancements, which are documented in the Release Notes document linked in the References.

Security Fix(es):

  • commons-text: apache-commons-text: variable interpolation (CVE-2022-42889)

  • org.eclipse.milo-sdk-server: sdk-server: Denial of Service (CVE-2022-25897)

  • reactor-netty-http: Log request headers in some cases of invalid HTTP requests (CVE-2022-31684)

For more details about the security issues, including the impact, CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.