Lucene search

K
redhatRedHatRHSA-2023:1177
HistoryMar 09, 2023 - 10:45 a.m.

(RHSA-2023:1177) Important: Red Hat Integration Camel Extension For Quarkus 2.7-1 security update

2023-03-0910:45:20
access.redhat.com
25
red hat integration
camel extension
quarkus 2.7-1
security update
xstream
postgresql-jdbc
denial of service
information leak
cve-2022-41966
cve-2022-41946
references

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

EPSS

0.01

Percentile

83.8%

A security update for Red Hat Integration Camel Extensions for Quarkus 2.7-1 is now available.

Security Fix(es):

  • xstream: Denial of Service by injecting recursive collections or maps based on element’s hash values raising a stack overflow (CVE-2022-41966)

  • postgresql-jdbc: Information leak of prepared statement data due to insecure temporary file permissions (CVE-2022-41946)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

EPSS

0.01

Percentile

83.8%