Red Hat Security Advisory: HawtIO 4.2.0 for Red Hat build of Apache Camel 4 Release and security update.
🔗 CVE IDs covered (5)
📋 Description
CVE-2024-12397 — io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling
CVE-2024-52798 — path-to-regexp: path-to-regexp Unpatched path-to-regexp ReDoS in 0.1.x
CVE-2024-57699 — json-smart: Potential DoS via stack exhaustion (incomplete fix for CVE-2023-1370)
CVE-2025-22866 — crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec
CVE-2025-24970 — io.netty:netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine
🎯 Affected products1
- HawtIO HawtIO 4.2.0
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Currently, no mitigation is available for this vulnerability. Workaround: Avoid using two parameters within a single path segment when the separator is not, for example, /:a-:b. Alternatively, you can define the regex used for both parameters and ensure they do not overlap to allow backtracking. Workaround: Red Hat Product Security does not have a recommended mitigation at this time. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2025:8761
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2330689
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2331298
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2344073
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2344219
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2344787
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_8761.json