[UPDATE] [high] Red Hat Integration Camel for Spring Boot: Multiple vulnerabilities
A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Integration Camel for Spring Boot to compromise confidentiality, availability and integrity.
CSIRTS triage
- What
- Multiple vulnerabilities allow remote anonymous attackers to compromise confidentiality, availability, and integrity through code execution and security bypass.
- Who is affected
- All deployments of Red Hat Integration Camel for Spring Boot.
- Urgency
- High; remote exploitation affecting core security properties and availability.
- Action
- Update Red Hat Integration Camel for Spring Boot to patch CVE-2021-37533, CVE-2022-25857, CVE-2022-31777, CVE-2022-33681, CVE-2022-37865, CVE-2022-37866, CVE-2022-38398, CVE-2022-38648.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Integration Camel for Spring Boot
Get an email when a new Integration Camel for Spring Boot advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-1142
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2021-375331.9% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 77% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-258572.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 81% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-317771.5% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 73% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2022-336810.60% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-378651.8% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 76% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-378661.5% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 73% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-383982.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 80% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-386482.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 79% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-387491.7% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 74% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-387501.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 61% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] Oracle PeopleSoft: Multiple Vulnerabilitiescert-bund
- high[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Jira: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Atlassian products (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira): Multiple vuln…cert-bund
- high[UPDATE] [high] IBM Security Verify Access: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Red Hat JBoss Enterprise Application Platform: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] FasterXML Jackson: Multiple vulnerabilities allow Denial of Servicecert-bund
- unknownJenkins Security Advisory 2023-03-08jenkins
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] GStreamer: Multiple Vulnerabilities2026-08-17
- high[NEW] [high] Golang Go: Multiple vulnerabilities2026-08-17
- medium[NEW] [medium] Apache Struts: Multiple vulnerabilities2026-08-17
- high[NEW] [high] PostgreSQL: Multiple vulnerabilities2026-08-17
- high[UPDATE] [high] Oracle PeopleSoft: Multiple Vulnerabilities2026-08-17