RHSA-2024:7972CriticalCVSS 8.8
Red Hat Security Advisory: Red Hat Build of Apache Camel 4.4 for Quarkus 3.8 update is now available (RHBQ 3.8.6.SP1)
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-7254 — protobuf: StackOverflow vulnerability in Protocol Buffers CVE-2024-47561 — apache-avro: Schema parsing may trigger Remote Code Execution (RCE)
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2024:7972
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2313454
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2316116
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_7972.json