-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Low: Red Hat Integration Camel Extensions for Quarkus 2.13.3-1 security update
Advisory ID:       RHSA-2023:5310-01
Product:           Red Hat Integration
Advisory URL:      https://access.redhat.com/errata/RHSA-2023:5310
Issue date:        2023-09-20
CVE Names:         CVE-2023-4853 
=====================================================================

1. Summary:

Red Hat Integration Camel Extensions for Quarkus 2.13.3-1 release and
security update is now available.

Red Hat Product Security has rated this update as having an impact of Low.
A Common Vulnerability Scoring System (CVSS) base score, which gives a
detailed severity rating, is available for each vulnerability from the CVE
link(s) in the References section.

2. Description:

A security update for Camel Extensions for Quarkus 2.13.3 is now available.

The purpose of this text-only errata is to inform you about the security
issues fixed.

Security Fix(es):

* quarkus-vertx-http: quarkus: HTTP security policy bypass (CVE-2023-4853)

Red Hat Product Security has issued a Security Bulletin regarding this
flaw. See the RHSB link in the References section.

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

4. Bugs fixed (https://bugzilla.redhat.com/):

2238034 - CVE-2023-4853 quarkus: HTTP security policy bypass

5. References:

https://access.redhat.com/security/cve/CVE-2023-4853
https://access.redhat.com/security/updates/classification/#low
https://access.redhat.com/security/vulnerabilities/RHSB-2023-002
https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2023-Q3

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJlCrrlAAoJENzjgjWX9erEiNMP/3LaxCkr/bc45RtmAMwoazjD
dTZN2XxbYGK+Rk7QGIeaxCHYqPpNvZ218nt+aoK6RD3ZxOxpce0VYphbHLQcmqFg
JVezhDGiJfeAPfnwDL2r2ODRdYUzZpe1ZQDcId11MqP53mf6MT3OyjX/8oVDvl5Y
6UWpa1Kgs9iOsdadTes4qbW3DjAxXjNJM/sZLRnCx0GjH1w67xl3qzfmxE5vpkc9
0iBOMoWrqe8qapBFIfA5BkkS5tNZd3tq/muFW9PShZDcVmOLB5SHsyzzOa/68Rk5
knpCKk1wfWINITJf+MZdZ3VgSvQRX3PbXJSZ3OmIAYmnRFQm3IRGUZ5C8+zttkLd
J28WI8qNAYLc0cbsgS9UV11PaHnvRfptAD8x7Ux5BomCb60+2E9fFV5ThTHdPEwu
b4ZxatnbGxDiWl6FDHFZx32EWPFVR1lSlQVO8NPUoYMLr2kyR3/iSBztOuG8Qz+0
nE8AJQQurAtRXhk4O76beMGAIt42hNfY/Jn/R3wgIxJOoezJJ7QnL3RteokIOC5m
Tleuw6XJY2kQgOo8rx/M3Cs36bauSLgFJv5g5etqqTM0K173CT5RD/dVGzVzyfQY
s+KqysYZQjrX9Rl+n5v40t/RQgP2pEiCfkzMWXWgjg00ptpo9C74KYqYJ/mYKYDM
2xjcD81yiQtMVf7dELFa
=Sq5r
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2023-5310:01 Low: Red Hat Integration Camel Extensions for

Red Hat Integration Camel Extensions for Quarkus 2.13.3-1 release and security update is now available

Summary

A security update for Camel Extensions for Quarkus 2.13.3 is now available.
The purpose of this text-only errata is to inform you about the security issues fixed.
Security Fix(es):
* quarkus-vertx-http: quarkus: HTTP security policy bypass (CVE-2023-4853)
Red Hat Product Security has issued a Security Bulletin regarding this flaw. See the RHSB link in the References section.
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2023-4853 https://access.redhat.com/security/updates/classification/#low https://access.redhat.com/security/vulnerabilities/RHSB-2023-002 https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2023-Q3

Package List


Severity
Advisory ID: RHSA-2023:5310-01
Product: Red Hat Integration
Advisory URL: https://access.redhat.com/errata/RHSA-2023:5310
Issued Date: : 2023-09-20
CVE Names: CVE-2023-4853

Topic

Red Hat Integration Camel Extensions for Quarkus 2.13.3-1 release andsecurity update is now available.Red Hat Product Security has rated this update as having an impact of Low.A Common Vulnerability Scoring System (CVSS) base score, which gives adetailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

2238034 - CVE-2023-4853 quarkus: HTTP security policy bypass


Related News