-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Low: Red Hat Integration Camel Extensions for Quarkus 2.2.1-1 security update
Advisory ID:       RHSA-2022:1306-01
Product:           Red Hat Integration
Advisory URL:      https://access.redhat.com/errata/RHSA-2022:1306
Issue date:        2022-04-11
CVE Names:         CVE-2022-22965 
====================================================================
1. Summary:

A security update to Red Hat Integration Camel Extensions for Quarkus 2.2.1
is now available. The purpose of this text-only errata is to inform you
about the security issues fixed.

Red Hat Product Security has rated this update as having an impact of Low.
A Common Vulnerability Scoring System (CVSS) base score, which gives a
detailed severity rating, is available for each vulnerability from the CVE
link(s) in the References section.

2. Description:

Red Hat Integration - Camel Extensions for Quarkus 2.2.1-1 serves as a
replacement for 2.2.1 and includes the following security Fix(es):

Security Fix(es):

* spring-beans: spring-framework: RCE via Data Binding on JDK 9+
(CVE-2022-22965)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

4. Bugs fixed (https://bugzilla.redhat.com/):

2070348 - CVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+

5. References:

https://access.redhat.com/security/cve/CVE-2022-22965
https://access.redhat.com/security/updates/classification/#low
https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2022-Q1
https://access.redhat.com/security/vulnerabilities/RHSB-2022-003
https://access.redhat.com/documentation/en-us/red_hat_integration/2022.q1

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2022 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBYlRU8tzjgjWX9erEAQiVYw//df30qQGNcy/ZYVftL/HjhP1W6+2UWQlT
agKcDc65c2yb7K5drtq7zK8abiiIT8YoRmsHBRmjMDyql5yidTyzqkgOQsOYQmZB
z8wRFVnOxw+iYKja+XeoQI0/VlIhcMlyLK/taNvikM+Q68AWq2v7cmh1CyD+tmMI
R1b0WHIK0wpM2T1lZERDMaeCDNs0GI66EljOeCuOCB2+E46X9Eb9/Y9X8jhCgbZM
PL4QO2hLDyfI6xhjQ9K6aba6AHoT3buncmFnbOJ38vTLt/uOckzr+IrVG1P24TCY
VcPiW2jmJvcc9MlTEPMWw8PE7WPghF0qoPjaI1JdG+OLb4XAZAMydAOsRaz43Qke
v28anB1E6Jx/jmz5BmaBWSvp4Ka2HvQCKuD9VZaMRnKEUufwjxM0ydAxl9ldhSg+
AaSISSY/mjvY8/tc6fNuDDIkwNNCkZ1QK1A7yLbR4qVr1KfehU8TcBaoB2DbRkBt
Mq1uDTFdOeqJtM0UF2wZJ4HPLhaH/joZ9x4Bnj8iWB29S4mXiDoPoL4tXQ6PJWEZ
We5KwQTvDzw3XWnvO+AlUklOxEKLNHUGg0sDRA9OOted6kfMG9NrNc+4sRNxWHUt
tnhRs4szbHNcgd9z24MTkU8U9WPo82jiXgYOceXYTbv6wwEE6ALcKykv57e/vxN3
z9DZcMs3Zgw=zFOl
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2022-1306:01 Low: Red Hat Integration Camel Extensions for

A security update to Red Hat Integration Camel Extensions for Quarkus 2.2.1 is now available

Summary

Red Hat Integration - Camel Extensions for Quarkus 2.2.1-1 serves as a replacement for 2.2.1 and includes the following security Fix(es):
Security Fix(es):
* spring-beans: spring-framework: RCE via Data Binding on JDK 9+ (CVE-2022-22965)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2022-22965 https://access.redhat.com/security/updates/classification/#low https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2022-Q1 https://access.redhat.com/security/vulnerabilities/RHSB-2022-003 https://access.redhat.com/documentation/en-us/red_hat_integration/2022.q1

Package List


Severity
Advisory ID: RHSA-2022:1306-01
Product: Red Hat Integration
Advisory URL: https://access.redhat.com/errata/RHSA-2022:1306
Issued Date: : 2022-04-11
CVE Names: CVE-2022-22965

Topic

A security update to Red Hat Integration Camel Extensions for Quarkus 2.2.1is now available. The purpose of this text-only errata is to inform youabout the security issues fixed.Red Hat Product Security has rated this update as having an impact of Low.A Common Vulnerability Scoring System (CVSS) base score, which gives adetailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

2070348 - CVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+


Related News