RedHat: RHSA-2022-7257:01 Low: Red Hat Integration Camel-K 1.8.1 security
Summary
A minor version update is now available for Red Hat Camel K that includes
CVE fixes in the base images. Details are linked in the References section.
Security Fix(es):
* jetty: requests to the ConcatServlet and WelcomeFilter are able to access
protected resources within the WEB-INF directory (CVE-2021-28169)
* tika-core: incomplete fix for CVE-2022-30126 (CVE-2022-30973)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Summary
Solution
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
References
https://access.redhat.com/security/cve/CVE-2021-28169 https://access.redhat.com/security/cve/CVE-2022-30973 https://access.redhat.com/security/updates/classification/#low https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2022-Q4 https://access.redhat.com/documentation/en-us/red_hat_integration/2022.q4
Package List
Topic
A micro version update is now available for Red Hat Integration Camel K.The purpose of this text-only errata is to inform you about the securityissues fixed in this release.Red Hat Product Security has rated this update as having a security impactof Low. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Topic
Relevant Releases Architectures
Bugs Fixed
1971016 - CVE-2021-28169 jetty: requests to the ConcatServlet and WelcomeFilter are able to access protected resources within the WEB-INF directory
2099553 - CVE-2022-30973 tika-core: incomplete fix for CVE-2022-30126