apupier commented on code in PR #1142:
URL: https://github.com/apache/camel-website/pull/1142#discussion_r1494190003


##########
content/security/CVE-2024-22369.md:
##########
@@ -0,0 +1,18 @@
+---
+title: "Apache Camel Security Advisory - CVE-2024-22369"
+date: 2024-02-19T09:25:42+02:00
+url: /security/CVE-2024-22369.html
+draft: false
+type: security-advisory
+cve: CVE-2024-22369
+severity: HIGH
+summary: "Apache Camel: Camel-SQL: Unsafe Deserialization from 
JDBCAggregationRepository"
+description: "The Camel-SQL AggregationRepository is vulnerable to unsafe 
deserialization. Under specific conditions it is possible to deserialize 
malicious payload."
+mitigation: "Users are recommended to upgrade to version 4.4.0, which fixes 
the issue. If users are on the 4.0.x LTS releases stream, then they are 
suggested to upgrade to 4.0.4. If users are on 3.x, they are suggested to move 
to 3.21.4 or 3.22.1"
+credit: "This issue was discovered by Ziyang Chen from HuaWei Open Source 
Management Center, Pingtao Wei from HuaWei Open Source Management Center 
(finder) and Haoran Zhi from HuaWei Open Source Management Center"
+affected: From 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 
before 4.0.4, from 4.1.0 before 4.4.0.
+fixed: 3.21.4, 3.22.1, 4.0.4 and 4.4.0
+---
+
+The JIRA ticket: https://issues.apache.org/jira/browse/CAMEL-20303 refers to 
the various commits that resovoled the issue, and have more details.

Review Comment:
   ```suggestion
   The JIRA ticket: https://issues.apache.org/jira/browse/CAMEL-20303 refers to 
the various commits that resolved the issue, and have more details.
   ```



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to