{"id":22075,"date":"2022-03-23T20:18:27","date_gmt":"2022-03-23T16:18:27","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/166418\/RHSA-2022-1029-01.txt"},"modified":"2022-03-27T09:40:57","modified_gmt":"2022-03-27T05:10:57","slug":"red-hat-security-advisory-2022-1029-01","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/red-hat-security-advisory-2022-1029-01\/","title":{"rendered":"Red Hat Security Advisory 2022-1029-01"},"content":{"rendered":"<p dir=\"ltr\">&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>\nHash: SHA256<\/p>\n<p dir=\"ltr\">====================================================================<br \/>\nRed Hat Security Advisory<\/p>\n<p dir=\"ltr\">Synopsis: Important: Red Hat Integration Camel-K 1.6.4 release and security update<br \/>\nAdvisory ID: RHSA-2022:1029-01<br \/>\nProduct: Red Hat Integration<br \/>\nAdvisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:1029<br \/>\nIssue date: 2022-03-23<br \/>\nCVE Names: CVE-2020-8908 CVE-2020-15522 CVE-2020-27218<br \/>\nCVE-2021-3690 CVE-2021-20293 CVE-2021-21349<br \/>\nCVE-2021-26291 CVE-2021-28168 CVE-2021-28170<br \/>\nCVE-2021-33813 CVE-2022-24407<br \/>\n====================================================================<br \/>\n1. Summary:<\/p>\n<p dir=\"ltr\">A micro version update (from 1.6.3 to 1.6.4) is now available for Red Hat<br \/>\nIntegration Camel K that includes bug fixes and enhancements. The purpose<br \/>\nof this text-only errata is to inform you about the security issues fixed<br \/>\nin this release.<\/p>\n<p dir=\"ltr\">Red Hat Product Security has rated this update as having a security impact<br \/>\nof Important. A Common Vulnerability Scoring System (CVSS) base score,<br \/>\nwhich gives a detailed severity rating, is available for each vulnerability<br \/>\nfrom the CVE link(s) in the References section.<\/p>\n<p dir=\"ltr\">2. Description:<\/p>\n<p dir=\"ltr\">A micro version update (from 1.6.3 to 1.6.4) is now available for Red Hat<br \/>\nCamel K that includes bug fixes and enhancements, which are documented in<br \/>\nthe Release Notes document linked to in the References.<\/p>\n<p dir=\"ltr\">Security Fix(es):<\/p>\n<p dir=\"ltr\">* undertow: buffer leak on incoming websocket PONG message may lead to DoS<br \/>\n(CVE-2021-3690)<\/p>\n<p dir=\"ltr\">* maven: Block repositories using http by default (CVE-2021-26291)<\/p>\n<p dir=\"ltr\">* cyrus-sasl: failure to properly escape SQL input allows an attacker to<br \/>\nexecute arbitrary SQL commands (CVE-2022-24407)<\/p>\n<p dir=\"ltr\">* bouncycastle: Timing issue within the EC math library (CVE-2020-15522)<\/p>\n<p dir=\"ltr\">* jetty: buffer not correctly recycled in Gzip Request inflation<br \/>\n(CVE-2020-27218)<\/p>\n<p dir=\"ltr\">* RESTEasy: PathParam in RESTEasy can lead to a reflected XSS attack<br \/>\n(CVE-2021-20293)<\/p>\n<p dir=\"ltr\">* XStream: SSRF can be activated unmarshalling with XStream to access data<br \/>\nstreams from an arbitrary URL referencing a resource in an intranet or the<br \/>\nlocal host (CVE-2021-21349)<\/p>\n<p dir=\"ltr\">* jersey: Local information disclosure via system temporary directory<br \/>\n(CVE-2021-28168)<\/p>\n<p dir=\"ltr\">* jakarta-el: ELParserTokenManager enables invalid EL expressions to be<br \/>\nevaluate (CVE-2021-28170)<\/p>\n<p dir=\"ltr\">* jdom: XXE allows attackers to cause a DoS via a crafted HTTP request<br \/>\n(CVE-2021-33813)<\/p>\n<p dir=\"ltr\">* guava: local information disclosure via temporary directory created with<br \/>\nunsafe permissions (CVE-2020-8908)<\/p>\n<p dir=\"ltr\">For more details about the security issue(s), including the impact, a CVSS<br \/>\nscore, acknowledgments, and other related information, refer to the CVE<br \/>\npage(s) listed in the References section.<\/p>\n<p dir=\"ltr\">3. Solution:<\/p>\n<p dir=\"ltr\">Before applying this update, make sure all previously released errata<br \/>\nrelevant to your system have been applied.<\/p>\n<p dir=\"ltr\">For details on how to apply this update, refer to:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/articles\/11258<\/p>\n<p dir=\"ltr\">4. Bugs fixed (https:\/\/bugzilla.redhat.com\/):<\/p>\n<p dir=\"ltr\">1902826 &#8211; CVE-2020-27218 jetty: buffer not correctly recycled in Gzip Request inflation<br \/>\n1906919 &#8211; CVE-2020-8908 guava: local information disclosure via temporary directory created with unsafe permissions<br \/>\n1942635 &#8211; CVE-2021-21349 XStream: SSRF can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host<br \/>\n1942819 &#8211; CVE-2021-20293 RESTEasy: PathParam in RESTEasy can lead to a reflected XSS attack<br \/>\n1953024 &#8211; CVE-2021-28168 jersey: Local information disclosure via system temporary directory<br \/>\n1955739 &#8211; CVE-2021-26291 maven: Block repositories using http by default<br \/>\n1962879 &#8211; CVE-2020-15522 bouncycastle: Timing issue within the EC math library<br \/>\n1965497 &#8211; CVE-2021-28170 jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate<br \/>\n1973413 &#8211; CVE-2021-33813 jdom: XXE allows attackers to cause a DoS via a crafted HTTP request<br \/>\n1991299 &#8211; CVE-2021-3690 undertow: buffer leak on incoming websocket PONG message may lead to DoS<br \/>\n2055326 &#8211; CVE-2022-24407 cyrus-sasl: failure to properly escape SQL input allows an attacker to execute arbitrary SQL commands<\/p>\n<p dir=\"ltr\">5. References:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/security\/cve\/CVE-2020-8908<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-15522<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-27218<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3690<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-20293<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-21349<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-26291<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-28168<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-28170<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-33813<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-24407<br \/>\nhttps:\/\/access.redhat.com\/security\/updates\/classification\/#important<br \/>\nhttps:\/\/access.redhat.com\/jbossnetwork\/restricted\/listSoftware.html?downloadType=distributions&amp;product=red.hat.integration&amp;version 22-Q2<br \/>\nhttps:\/\/access.redhat.com\/documentation\/en-us\/red_hat_integration\/2022.q2<\/p>\n<p dir=\"ltr\">6. Contact:<\/p>\n<p dir=\"ltr\">The Red Hat security contact is &lt;secalert@redhat.com&gt;. More contact<br \/>\ndetails at https:\/\/access.redhat.com\/security\/team\/contact\/<\/p>\n<p dir=\"ltr\">Copyright 2022 Red Hat, Inc.<br \/>\n&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<br \/>\nVersion: GnuPG v1<\/p>\n<p dir=\"ltr\">iQIVAwUBYjrohtzjgjWX9erEAQg6mg\/+LxmCCWt3OEzksRdLiypLvy5s2dvXoxGQ<br \/>\nlHMdzXoYiHb1OgYWYHYUFHzp25qFqI9VTPHeeBXHgb7RI3fN31m+Ao56F3QOfRIE<br \/>\nfWYS0W9BdCJQXLWzAfV1fvlLnrXLG3lCACouGvxy9WjRnF4e9S67STeEM+Hl\/NQw<br \/>\nXJkbUDQgJUxt97xGS6HZGtHoNxM4PnF8vN2VXBnOTOiTf3bsPToIW6RAS\/EzyoFb<br \/>\nwEoTX36QxktjT9WbAcAq1cErZl5qTx1kSkwguWfFCCUy4rfS8hh0G03nVTYCMY+l<br \/>\nGnwV7RUWQklDQ2n7r3HW36k+Dt3FoOhvezSkJTjPtuPSKaXwTtRnOeh4PcGyxgHO<br \/>\n07jYflxDYfkHmY81R\/Pel\/SFOy4JzyOr5Zyc2SntK9y6qEoAj46HEr\/IMH0WVE9h<br \/>\nK5i6HFPkDJtWDFxe729ctNjLdF2YLXzIjnFt0dJdE3CHbNIFItoj+L2zMh+2qvHO<br \/>\nlWElB2WvOIc4pKUCJxV6R2pOBrZwjwrD91PMGC00Ze5p8YsmkGgW9rMNTl+479fQ<br \/>\nEaYNj0JOAN1gxnYYfKxW\/SASi7fINl1xVn\/JnHV9ovPiKyqGPcTPNDJ+qvW1tsIj<br \/>\nBOmtIt9qAZH\/+xaY\/mj2E84aMghXobYB52Dw4iWgvPpPd9QMt17P2JTAxVQ0XWLr<br \/>\n1rOJAKvdRbU=vCKh<br \/>\n&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<br \/>\n&#8212;<br \/>\nRHSA-announce mailing list<br \/>\nRHSA-announce@redhat.com<br \/>\nhttps:\/\/listman.redhat.com\/mailman\/listinfo\/rhsa-announce<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211; Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Integration Camel-K 1.6.4 release and security update Advisory ID: RHSA-2022:1029-01 Product: Red Hat Integration Advisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:1029 Issue date: 2022-03-23 CVE Names: CVE-2020-8908 CVE-2020-15522 CVE-2020-27218 CVE-2021-3690 CVE-2021-20293 CVE-2021-21349 CVE-2021-26291 CVE-2021-28168 CVE-2021-28170 CVE-2021-33813 CVE-2022-24407 ==================================================================== 1. Summary: A micro version update &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-22075","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/22075","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=22075"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/22075\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=22075"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=22075"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=22075"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}