Lucene search

K
redhatRedHatRHSA-2024:2852
HistoryMay 15, 2024 - 10:09 a.m.

(RHSA-2024:2852) Important: Red Hat Build of Apache Camel 4.0 for Quarkus 3.2 update is now available (RHBQ 3.2.12.GA)

2024-05-1510:09:54
access.redhat.com
39
red hat
apache camel
quarkus
security
stability
enhancement

CVSS3

9.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

26.8%

An update for Red Hat Build of Apache Camel 4.0 for Quarkus 3.2 update is now available (RHBQ 3.2.12.GA).
The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products.
:

  • TRIAGE CVE-2024-28752 cxf-core: Apache CXF SSRF Vulnerability using the Aegis databinding
  • TRIAGE CVE-2024-2700 quarkus-core: Leak of local configuration properties into Quarkus applications

CVSS3

9.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

26.8%