{"id":22085,"date":"2022-03-23T21:19:30","date_gmt":"2022-03-23T17:19:30","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/166408\/RHSA-2022-1013-01.txt"},"modified":"2022-03-27T09:38:14","modified_gmt":"2022-03-27T05:08:14","slug":"red-hat-security-advisory-2022-1013-01","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/red-hat-security-advisory-2022-1013-01\/","title":{"rendered":"Red Hat Security Advisory 2022-1013-01"},"content":{"rendered":"<p dir=\"ltr\">&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>\nHash: SHA256<\/p>\n<p dir=\"ltr\">=====================================================================<br \/>\nRed Hat Security Advisory<\/p>\n<p dir=\"ltr\">Synopsis: Moderate: Red Hat Integration Camel Extensions for Quarkus 2.2.1 security update<br \/>\nAdvisory ID: RHSA-2022:1013-01<br \/>\nProduct: Red Hat Integration<br \/>\nAdvisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:1013<br \/>\nIssue date: 2022-03-22<br \/>\nCVE Names: CVE-2020-8908 CVE-2020-15522 CVE-2021-2471<br \/>\nCVE-2021-4178 CVE-2021-22569 CVE-2021-26291<br \/>\nCVE-2021-28168 CVE-2021-28170 CVE-2021-30129<br \/>\nCVE-2021-37136 CVE-2021-37137 CVE-2021-40690<br \/>\nCVE-2021-41269 CVE-2021-42392<br \/>\n=====================================================================<\/p>\n<p dir=\"ltr\">1. Summary:<\/p>\n<p dir=\"ltr\">A security update to Red Hat Integration Camel Extensions for Quarkus 2.2<br \/>\nis now available. The purpose of this text-only errata is to inform you<br \/>\nabout the security issues fixed.<\/p>\n<p dir=\"ltr\">Red Hat Product Security has rated this update as having an impact of<br \/>\nModerate. A Common Vulnerability Scoring System (CVSS) base score, which<br \/>\ngives a detailed severity rating, is available for each vulnerability from<br \/>\nthe CVE link(s) in the References section.<\/p>\n<p dir=\"ltr\">2. Description:<\/p>\n<p dir=\"ltr\">Red Hat Integration &#8211; Camel Extensions for Quarkus 2.2.1 serves as a<br \/>\nreplacement for 2.2 and includes the following security Fix(es):<\/p>\n<p dir=\"ltr\">Security Fix(es):<\/p>\n<p dir=\"ltr\">* cron-utils: template Injection leading to unauthenticated Remote Code<br \/>\nExecution (CVE-2021-41269)<\/p>\n<p dir=\"ltr\">* maven: Block repositories using http by default (CVE-2021-26291)<\/p>\n<p dir=\"ltr\">* bouncycastle: Timing issue within the EC math library (CVE-2020-15522)<\/p>\n<p dir=\"ltr\">* mysql-connector-java: unauthorized access to critical (CVE-2021-2471)<\/p>\n<p dir=\"ltr\">* kubernetes-client: Insecure deserialization in unmarshalYaml method<br \/>\n(CVE-2021-4178)<\/p>\n<p dir=\"ltr\">* protobuf-java: potential DoS in the parsing procedure for binary data<br \/>\n(CVE-2021-22569)<\/p>\n<p dir=\"ltr\">* jersey: Local information disclosure via system temporary directory<br \/>\n(CVE-2021-28168)<\/p>\n<p dir=\"ltr\">* jakarta-el: ELParserTokenManager enables invalid EL expressions to be<br \/>\nevaluate (CVE-2021-28170)<\/p>\n<p dir=\"ltr\">* mina-sshd-core: Memory leak denial of service in Apache Mina SSHD Server<br \/>\n(CVE-2021-30129)<\/p>\n<p dir=\"ltr\">* netty-codec: Bzip2Decoder doesn&#8217;t allow setting size restrictions for<br \/>\ndecompressed data (CVE-2021-37136)<\/p>\n<p dir=\"ltr\">* netty-codec: SnappyFrameDecoder doesn&#8217;t restrict chunk length and may<br \/>\nbuffer skippable chunks in an unnecessary way (CVE-2021-37137)<\/p>\n<p dir=\"ltr\">* xml-security: XPath Transform abuse allows for information disclosure<br \/>\n(CVE-2021-40690)<\/p>\n<p dir=\"ltr\">* h2: Remote Code Execution in Console (CVE-2021-42392)<\/p>\n<p dir=\"ltr\">* guava: local information disclosure via temporary directory created with<br \/>\nunsafe permissions (CVE-2020-8908)<\/p>\n<p dir=\"ltr\">For more details about the security issue(s), including the impact, a CVSS<br \/>\nscore, acknowledgments, and other related information, refer to the CVE<br \/>\npage(s) listed in the References section.<\/p>\n<p dir=\"ltr\">3. Solution:<\/p>\n<p dir=\"ltr\">Before applying this update, make sure all previously released errata<br \/>\nrelevant to your system have been applied.<\/p>\n<p dir=\"ltr\">For details on how to apply this update, refer to:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/articles\/11258<\/p>\n<p dir=\"ltr\">4. Bugs fixed (https:\/\/bugzilla.redhat.com\/):<\/p>\n<p dir=\"ltr\">1906919 &#8211; CVE-2020-8908 guava: local information disclosure via temporary directory created with unsafe permissions<br \/>\n1953024 &#8211; CVE-2021-28168 jersey: Local information disclosure via system temporary directory<br \/>\n1955739 &#8211; CVE-2021-26291 maven: Block repositories using http by default<br \/>\n1962879 &#8211; CVE-2020-15522 bouncycastle: Timing issue within the EC math library<br \/>\n1965497 &#8211; CVE-2021-28170 jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate<br \/>\n1981527 &#8211; CVE-2021-30129 mina-sshd-core: Memory leak denial of service in Apache Mina SSHD Server<br \/>\n2004133 &#8211; CVE-2021-37136 netty-codec: Bzip2Decoder doesn&#8217;t allow setting size restrictions for decompressed data<br \/>\n2004135 &#8211; CVE-2021-37137 netty-codec: SnappyFrameDecoder doesn&#8217;t restrict chunk length and may buffer skippable chunks in an unnecessary way<br \/>\n2011190 &#8211; CVE-2021-40690 xml-security: XPath Transform abuse allows for information disclosure<br \/>\n2020583 &#8211; CVE-2021-2471 mysql-connector-java: unauthorized access to critical<br \/>\n2024632 &#8211; CVE-2021-41269 cron-utils: template Injection leading to unauthenticated Remote Code Execution<br \/>\n2034388 &#8211; CVE-2021-4178 kubernetes-client: Insecure deserialization in unmarshalYaml method<br \/>\n2039403 &#8211; CVE-2021-42392 h2: Remote Code Execution in Console<br \/>\n2039903 &#8211; CVE-2021-22569 protobuf-java: potential DoS in the parsing procedure for binary data<\/p>\n<p dir=\"ltr\">5. References:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/security\/cve\/CVE-2020-8908<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-15522<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-2471<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-4178<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-22569<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-26291<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-28168<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-28170<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-30129<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-37136<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-37137<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-40690<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-41269<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-42392<br \/>\nhttps:\/\/access.redhat.com\/security\/updates\/classification\/#moderate<br \/>\nhttps:\/\/access.redhat.com\/jbossnetwork\/restricted\/listSoftware.html?downloadType=distributions&#038;product=red.hat.integration&#038;version=2022-Q2<br \/>\nhttps:\/\/access.redhat.com\/documentation\/en-us\/red_hat_integration\/2022.q2<\/p>\n<p dir=\"ltr\">6. Contact:<\/p>\n<p dir=\"ltr\">The Red Hat security contact is &lt;secalert@redhat.com&gt;. More contact<br \/>\ndetails at https:\/\/access.redhat.com\/security\/team\/contact\/<\/p>\n<p dir=\"ltr\">Copyright 2022 Red Hat, Inc.<br \/>\n&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<br \/>\nVersion: GnuPG v1<\/p>\n<p dir=\"ltr\">iQIVAwUBYjo\/xNzjgjWX9erEAQiYmw\/\/eZoz1n10qXWkDZC56hNFD0KoHC8dw\/hT<br \/>\nyqUEnK0evdK7M0mYDxdVfEkVCEIH587nIWxtJboSftCIeTYkdTTej8gyCvvfv4Jf<br \/>\nJWjbLyvgLA5GUzsnWHLzd3wzuYJvL5aRAzmyYeG4ki08xjqki8qTGVheEQRph+ND<br \/>\ndJzZrZAlklCavZfEq0X4Vgny816pcPcr0Gv6yUfMEtzGlRhFxdb4JVmLoz9RvuNG<br \/>\nqOYSwd6Z9rR1XAjdoxaZsJj9\/30Zp5OmpP3\/2GyxQoenKAwzw4lZkQpDmsKnzgL\/<br \/>\nfVeAU1HBDp8mUKw06GFnGr\/vrhOMTbsOzCnr1iatzIQRmT9Cqbjy8czSXbkoLEn4<br \/>\nQiCFQuNK5H664fiJ18L48motc8+pcy\/tQH7f7QOGmsx+KdYGjGHd8k7etlKWKuyI<br \/>\nu47JZ\/wDCeanvEBTg4kZrzWZgZcVPXTC0kpsIerXap+NRHDR4XhlLj7OYjnIifVU<br \/>\ncQ6S2qZ3RdQWiqF\/fLs55EHT04nf7ew436QcuqO7zWrOtOX\/KU2SrYJ5x93CgIrA<br \/>\nwbA6PirYDm21rzMoN+zRiAs3hkrKwkNKLyUgV7tL9bIKOoMTme+EnsSI+KPal2j8<br \/>\ngNqeqN9tshVy19e9NX1pUaZsnVkf+gdfOb5SMuCWZAZEg+n2cb3QSTU8fCd1ob0p<br \/>\nMlDo83beSGY=<br \/>\n=EXhy<br \/>\n&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<br \/>\n&#8212;<br \/>\nRHSA-announce mailing list<br \/>\nRHSA-announce@redhat.com<br \/>\nhttps:\/\/listman.redhat.com\/mailman\/listinfo\/rhsa-announce<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211; Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat Integration Camel Extensions for Quarkus 2.2.1 security update Advisory ID: RHSA-2022:1013-01 Product: Red Hat Integration Advisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:1013 Issue date: 2022-03-22 CVE Names: CVE-2020-8908 CVE-2020-15522 CVE-2021-2471 CVE-2021-4178 CVE-2021-22569 CVE-2021-26291 CVE-2021-28168 CVE-2021-28170 CVE-2021-30129 CVE-2021-37136 CVE-2021-37137 CVE-2021-40690 CVE-2021-41269 CVE-2021-42392 ===================================================================== 1. Summary: &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-22085","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/22085","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=22085"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/22085\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=22085"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=22085"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=22085"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}