-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Integration Camel Extensions For Quarkus 2.13.2-2 security update Advisory ID: RHSA-2023:3179-01 Product: Red Hat Integration Advisory URL: https://access.redhat.com/errata/RHSA-2023:3179 Issue date: 2023-05-17 CVE Names: CVE-2023-1370 ==================================================================== 1. Summary: Red Hat Integration Camel Extensions for Quarkus 2.13.2-2 release and security update is now available. The purpose of this text-only errata is to inform you about the security issues fixed. Red Hat Product Security has rated this update as having an impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: A security update for Camel Extensions for Quarkus 2.13.2-2 is now available. The purpose of this text-only errata is to inform you about the security issues fixed. Security Fix(es): * json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) (CVE-2023-1370) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). 4. Bugs fixed (https://bugzilla.redhat.com/): 2188542 - CVE-2023-1370 json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) 5. References: https://access.redhat.com/security/cve/CVE-2023-1370 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version 23-Q2 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZGUUlNzjgjWX9erEAQg5ZQ//VLp3h0qYtn+T+CRXNNGUmWidLP2g0udw dCDTM5JPvQZXOxVBgFXQlxhmo/EqY2SRTAVf+v1e7YK3g4Zzwpkf0eK4BDk8LVuA 4lTMvL0PxWmk0Th68qRFoy4gtRnrBTPg02wwi/EGdD9DvOAUCB+SnBRQA+p2fd5c itRA/Z/w6sQNukYgGv4fP9H/c4Werjpgn0RY21z8UXAXkJZRt9qp3ilKvZawfr0X xERjE+tmhj1QFqWriSBFFpG9xvKFoeUD+Oozxu6q+1d6BfRMPUnR0JWGoiI7JZd5 VD0Bto4YrmQKTv16e9JqBYCEEYfbfv6rQSyUKAghBFDg24tkKu6YcyQwsNpZM8Re XlBV5FRFBOvNjUT8UW3VXHyt4OARAbAaIInSgWF4nP0dCyhIuCPzdSglOvUuU4cy xhRUxhhJ1i2NA6541yCBQrExTnuPYaLQQrhnYghCNLZhr1JdvRwO9dWSBxajrb1M WcVKdOzqMZ4piq38s7uOVh2m159daX6v0jQDcWPqYd2rMCuVy4Mc+Ee2j7Uonf7o higxE/WpQiiX1KfPNtX1dEI/fGUI+inFyJFK6ZnGdxAISXXCh4G7xEkhtNVAKLWq IQzVrxmsxbixb6UYyMsQ2z9iCPbF8iL4mO887mE6pR74ZOBIV1EpleXWgdWurmt0 4XPHD7Ui0yk=R0dS -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce