RHSA-2023:7617HighCVSS 7.5

Red Hat Security Advisory: Red Hat Build of Apache Camel for Quarkus 3.2.0 release (RHBQ 3.2.9.Final)

Published
November 30, 2023
Last Modified
September 14, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2023-5072 — JSON-java: parser confusion leads to OOM CVE-2023-39410 — apache-avro: Apache Avro Java SDK: Memory when deserializing untrusted data in Avro Java SDK

🎯 Affected products1

  • Red Hat build of Apache Camel 4 for Quarkus 3

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: No current mitigation is available for this flaw.

🔗 References (6)