The vendor explicitly identifies these products as affected by this CVE.
- apache-johnzon as a component of Red Hat build of Apache Camel for Spring Boot 3
- apache-johnzon as a component of Red Hat Decision Manager 7
- apache-johnzon as a component of Red Hat Fuse 7
- apache-johnzon as a component of Red Hat Integration Camel K 1
- apache-johnzon as a component of Red Hat Integration Camel Quarkus 2
- apache-johnzon as a component of Red Hat JBoss Data Grid 7
- apache-johnzon as a component of Red Hat Process Automation 7
- Summary
- A flaw was found in Apache Johnzon. This issue could allow an attacker to craft a specific JSON input that Johnzon will deserialize into a BigDecimal, which Johnzon may use to start converting large numbers, resulting in a denial of service.
- Remediation
- Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings. The References section of this erratum contains a download link (you must log in to download the update).
