SB2025021123 - Multiple vulnerabilities in Red Hat Integration Camel Extensions for Quarkus 3.15



SB2025021123 - Multiple vulnerabilities in Red Hat Integration Camel Extensions for Quarkus 3.15

Published: February 11, 2025

Security Bulletin ID SB2025021123
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Resource management error (CVE-ID: CVE-2024-47535)

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to an unsafe reading of an environment file on Windows. A local user can create an overly large file and perform a denial of service (DoS) attack.


2) Input validation error (CVE-ID: CVE-2024-12397)

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient validation of cookies with certain value-delimiting characters in incoming requests in Quarkus-HTTP. A remote attacker can construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification.


Remediation

Install update from vendor's website.