Chapter 8. Fixed Issues in Fuse 7.12

The following sections list the issues that have been fixed in Fuse 7.12:

8.1. Enhancements in Fuse 7.12

IssueDescription

ENTESB-17374

Expose loaded plugins to avoid multiple requests to PluginServlet

ENTESB-20016

Fuse Console - Allow the possibility to set label at the hawtio CR

ENTESB-20592

Certify Fuse 7 on OpenJDK 17 before ELS

ENTESB-20667

operators.openshift.io/valid-subscription annotation for operator metadata bundles

ENTESB-20714

ensure all CXF tests passed with JDK17

ENTESB-20830

Certify Fuse 7 on RHEL 9

ENTESB-20953

Upgrade to EAP-7.4.10.GA-redhat-00002

8.2. Component Upgrades in Fuse 7.12

The following table lists the component upgrades in Fuse 7.12.

Table 8.1. Fuse 7.12 Component Upgrades

IssueDescription

ENTESB-20648

Upgrade Spring Boot to 2.7.12

ENTESB-20849

Align camel test dependencies to be compatible with JDK17

ENTESB-21063

Align to kafka-clients v3

8.3. Bugs resolved in Fuse 7.12

The following tables list the resolved bugs in Fuse 7.12.

Table 8.2. Fuse 7.12 Resolved Bugs

IssueDescription

ENTESB-8337

Offline repository contains org.jboss.fuse.fis.archetypes group name artfacts

ENTESB-12949

Next button disabled in SQS step creation until I change the autopopulated queue value

ENTESB-13046

Restore using operator binary not working as expected

ENTESB-13366

Operator instructions unclear and secret create steps are not easy to debug

ENTESB-13966

Discovery of deployed integration API seems disabled but not really

ENTESB-14552

support for multicast queue

ENTESB-17394

Error exclamation marks doesn’t show error message

ENTESB-17404

Build leveldb-jni for x86

ENTESB-17888

validation error when connecting to an https endpoint

ENTESB-18042

Failed to watch errors printed in the operator logs

ENTESB-18364

Hawtio - CSP issues when using Hawtio with Keycloak

ENTESB-19351

FIPS on OCP - Jolokia agent doesn’t start due to unsupported security encoding

ENTESB-19352

FIPS on OCP - karaf-maven-plugin assembly goal fails to unsupported security provider

ENTESB-19745

Quickstart spring-boot-camel-amq integrations tests references old AMQ Broker version

ENTESB-19757

Provide a source container image for apicurito

ENTESB-19956

[Syndesis] CVE-2022-24785 Moment.js: Path traversal in moment.locale [fuse-7]

ENTESB-19986

Fuse hawtio includes HTTPClient 3.1 - CVE-2012-5783

ENTESB-20096

AMQ6 image - V2 schema 1 manifest digest are no longer supported for image pulls

ENTESB-20175

Missing dataformats fhir-json/fhir-xml/xml-json in runtime specific catalogs

ENTESB-20177

Send correct UMB messages for container builds

ENTESB-20404

Camel http4 producer encodes array data to the http uri parameter as comma separated instead of multi-values parameters

ENTESB-20485

CVE-2022-42920 apache-bcel: Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing [fuse-7]

ENTESB-20595

Backport request for ENTMQCL-2977 to Fuse 7.11.x

ENTESB-20596

CVE-2022-41940 engine.io: Specially crafted HTTP request can trigger an uncaught exception [fuse-7]

ENTESB-20598

Incomplete fix of CVE-2020-13956

ENTESB-20618

CVE-2022-41881 codec-haproxy: HAProxyMessageDecoder Stack Exhaustion DoS [fuse-7]

ENTESB-20619

CVE-2022-41854 dev-java-snakeyaml: dev-java/snakeyaml: DoS via stack overflow [fuse-7]

ENTESB-20626

CVE-2022-40146 batik: Server-Side Request Forgery (SSRF) vulnerability [fuse-7]

ENTESB-20627

CVE-2022-38398 batik: Server-Side Request Forgery [fuse-7]

ENTESB-20628

CVE-2022-38648 batik: Server-Side Request Forgery [fuse-7]

ENTESB-20630

CVE-2022-46364 CXF: Apache CXF: SSRF Vulnerability [fuse-7]

ENTESB-20632

CVE-2022-46363 CXF: Apache CXF: directory listing / code exfiltration [fuse-7]

ENTESB-20637

CVE-2022-4492 undertow: Server identity in https connection is not checked by the undertow client [fuse-7]

ENTESB-20641

CVE-2022-41946 jdbc-postgresql: postgresql-jdbc: Information leak of prepared statement data due to insecure temporary file permissions [fuse-7]

ENTESB-20663

Errors during Karaf startup with jdk17

ENTESB-20664

Errors during EAP startup with jdk17

ENTESB-20672

CVE-2022-45143 tomcat: JsonErrorReportValve injection [fuse-7]

ENTESB-20690

CVE-2022-36437 hazelcast: Hazelcast connection caching [fuse-7]

ENTESB-20693

Review patch-maven-plugin → karaf-maven-plugin communication

ENTESB-20696

A custom fuse console route doesn’t work.

ENTESB-20697

AutomaticRecovery from RabbitMQ Connection Factory is always creating a new connection

ENTESB-20701

fuse-patch may incorrectly report that a patch has already been applied

ENTESB-20702

netty4-http forwards a bad response (exception + http code 200)

ENTESB-20710

CXF test errors after upgrading to Karaf 4.4 and Pax Web 8

ENTESB-20711

Any issue with camel-aws 2.23 component with TLS 1.3 in Fuse 7.11 ?

ENTESB-20712

Camel test errors after upgrading to Karaf 4.4 and Pax Web 8

ENTESB-20720

Multicast not returning aggregated

ENTESB-20726

Hazelcast upgrade seems to break JCache Integration

ENTESB-20741

Wrong javax/mail/mail version used in fuse projects.

ENTESB-20742

Wrong log4j-slf4j18-impl version is used fuse projects.

ENTESB-20754

[Hawtio] Can’t login in Karaf

ENTESB-20826

CVE-2022-41966 xstream: Denial of Service by injecting recursive collections or maps based on element’s hash values raising a stack overflow [fuse-7]

ENTESB-20828

cxf - server transport isn’t up properly

ENTESB-20829

[Karaf] JCE cannot authenticate the provider BC

ENTESB-20831

Use groupified API versions in json files

ENTESB-20835

Karaf pax web - OPTIONS methods not exposed

ENTESB-20836

Hibernate fuse version clashes with spring boot

ENTESB-20839

[Karaf] JMX ACL MBean authentification problem

ENTESB-20840

[Karaf] 10 features cannot be installed

ENTESB-20841

Fuse archetype Spring Boot properties in SB1 format

ENTESB-20842

camel-master component is unable to load cluster service

ENTESB-20845

CVE-2023-1108 undertow: Infinite loop in SslConduit during close [fuse-7]

ENTESB-20847

[Karaf] Jasypt encryption problem JDK 17 and RHEL8-FIPS

ENTESB-20850

[Standalone] No response messages via fuse client

ENTESB-20851

[Standalone] Colorised commands in history

ENTESB-20853

[Fuse on Openshift] - Wrong Docker image reference in Quickstarts

ENTESB-20854

[Fuse on Openshift] - Application templates - No tag "1.12" with image streams in fis-image-streams.json

ENTESB-20855

[Fuse on Openshift] - Wrong WILDFLY version in EAP images JDK8/11

ENTESB-20857

[Fuse on Openshift] - Application templates - Templates filled with old 7.11 references

ENTESB-20859

[Patching] Unable to patch 7.11 to 7.12

ENTESB-20862

[karaf FoO] unable to use client into the POD

ENTESB-20869

CVE-2023-20860 springframework: Security Bypass With Un-Prefixed Double Wildcard Pattern [fuse-7]

ENTESB-20870

CVE-2023-20861 springframework: Spring Expression DoS Vulnerability [fuse-7]

ENTESB-20871

Camel 2.23 tests do not support jdk17

ENTESB-20872

Wildfly Camel 5.10 tests do not support jdk17

ENTESB-20873

CXF 3.3.6 tests do not support jdk17

ENTESB-20950

[Karaf] Doesn’t install features

ENTESB-20951

Camel Mail Component doesn’t use host/port information from session URI parameter

ENTESB-20956

CVE-2022-4492, ensure that Syndesis is using fixed undertow

ENTESB-20957

CVE-2023-1108 undertow: Infinite loop in SslConduit during close (fuse online)

ENTESB-20958

CVE-2022-41704 batik: Apache XML Graphics Batik vulnerable to code execution via SVG [fuse-7]

ENTESB-20959

CVE-2022-42890 batik: Untrusted code execution in Apache XML Graphics Batik [fuse-7]

ENTESB-20960

CVE-2023-22602 shiro-core: shiro: Authentication bypass through a specially crafted HTTP request [fuse-7]

ENTESB-20961

[Fuse On Openshift] QS spring-boot-camel-amq contains a removed image

ENTESB-20963

[Fuse On Openshift] QS Spring-Boot Camel Rest SQL reports wrong deployment step in README

ENTESB-20964

[Fuse On Openshift] Adjust Pod metering label rht.prod_ver formatting

ENTESB-20967

[Fuse on Openshift] QS Spring-Boot Camel Config fails on Spring Cloud due to SB upgrade

ENTESB-20966

Unable to install karaf features separately

ENTESB-20968

[Fuse On Openshift] QS Spring-Boot Camel Rest SQL throws bad SQL grammar exception

ENTESB-20969

[Fuse On Openshift] QS Spring-Boot Camel XA throws bad SQL grammar exception on PostGresSQL connection

ENTESB-20971

Hawtio console metrics shows free memory instead of used

ENTESB-21045

Pax-web-jetty features cannot be installed

ENTESB-21046

[Fuse standalone] Exception in log jdk11 and jdk17

ENTESB-21047

CVE-2023-20860, ensure that Syndesis is using fixed springframework

ENTESB-21048

Cannot install CVE patch on top of 7.12

ENTESB-21049

CVE-2022-41854, ensure that Syndesis is using fixed snakeyaml

ENTESB-21050

Remove org.apache.tomcat.embed dependencies from cxf-spring-boot-starter-jaxrs

ENTESB-21051

[Fuse On Openshift] QS Spring-Boot Camel-Drools, unable to create Kie Server

ENTESB-21053

[Fuse on Openshift] QS Spring Boot Camel Singleton, app won’t start

ENTESB-21052

[Fuse on Openshift] - Karaf - Unable to resolve missing rquirement in a cxf-jaxrs application

ENTESB-21056

CVE-2023-20861, ensure that Syndesis is using fixed springframework

ENTESB-21057

CVE-2022-41946, ensure that Syndesis is using fixed jdbc-postgresql

ENTESB-21058

Karaf, some bundle versions are not inline with versions specified in karaf-bom

ENTESB-21059

Memory leak in pax-url-aether

ENTESB-21061

CXF 3.3.6 downstream failures

ENTESB-21704

CVE-2023-20863 springframework: Spring Expression DoS Vulnerability [fuse-7]

ENTESB-21158

Unattended Jolokia Queries Not Working When Keycloak is Integrated for Access Control

ENTESB-21161

[Offliner] Files cannot be downloaded using offliner manifest file

ENTESB-21162

[Offliner] Missing artifacts

ENTESB-21163

Apicurito pods contain metering labels with incorrect values

ENTESB-21168

CVE-2023-1370 json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) [fuse-7]

ENTESB-21272

[Fuse on Openshift] Wrong version in Quickstart BOM

ENTESB-21273

Remove or refactor non-working quickstart spring-boot-camel-soap-rest-bridge

ENTESB-21274

Wildfly camel 5.10.0 downstream failure

ENTESB-21304

[Fuse on Openshift] - Illegal access on java.xml module using Karaf, jaxws and JDK17, because xerces packages are not exposed

ENTESB-21309

[Fuse on Openshift] - In camel-jdbc on Karaf, can’t retrieve a column from the body exchange

ENTESB-21310

Camel-Velocity: Deprecation warnings

ENTESB-21311

SpringFramework caches a missed TypeConverter and user can not clean it

ENTESB-21316

[Fuse On Openshift] - Dismiss/Remove RHOSAK Quickstarts

ENTESB-21319

CVE-2022-31692 spring-security: Authorization rules can be bypassed via forward or include dispatcher types in Spring Security [fuse-7]

ENTESB-21322

Invalid qualifier for Karaf bundle

ENTESB-21332

CVE-2023-20883 spring-boot: Spring Boot Welcome Page DoS Vulnerability [fuse-7]

ENTESB-21335

patch-maven-plugin doesn’t work with Maven 3.9

ENTESB-21412

Missing refs/tags on GitHub

ENTESB-21415

[Fuse Standalone] Camel-chunk feature missing dependency

ENTESB-21417

CXF 3.3.6 downstream failures

ENTESB-21418

CVE-2023-1370, ensure that Syndesis is using fixed json-smart

ENTESB-21419

[Karaf] Jasypt encryption problem JDK 17 and RHEL8-FIPS

ENTESB-21421

Camel health check behaviour change on Spring Boot runtime