Chapter 8. Fixed Issues in Fuse 7.12


The following sections list the issues that have been fixed in Fuse 7.12 and Fuse 7.12.1:

8.1. Enhancements in Fuse 7.12

Expand
IssueDescription

ENTESB-17374

Expose loaded plugins to avoid multiple requests to PluginServlet

ENTESB-20016

Fuse Console - Allow the possibility to set label at the hawtio CR

ENTESB-20592

Certify Fuse 7 on OpenJDK 17 before ELS

ENTESB-20667

operators.openshift.io/valid-subscription annotation for operator metadata bundles

ENTESB-20714

ensure all CXF tests passed with JDK17

ENTESB-20830

Certify Fuse 7 on RHEL 9

ENTESB-20953

Upgrade to EAP-7.4.10.GA-redhat-00002

8.2. Component Upgrades in Fuse 7.12

The following table lists the component upgrades in Fuse 7.12.

Expand
Table 8.1. Fuse 7.12 Component Upgrades
IssueDescription

ENTESB-20648

Upgrade Spring Boot to 2.7.12

ENTESB-20849

Align camel test dependencies to be compatible with JDK17

ENTESB-21063

Align to kafka-clients v3

8.3. Bugs resolved in Fuse 7.12

The following tables list the resolved bugs in Fuse 7.12.

Expand
Table 8.2. Fuse 7.12 Resolved Bugs
IssueDescription

ENTESB-8337

Offline repository contains org.jboss.fuse.fis.archetypes group name artfacts

ENTESB-12949

Next button disabled in SQS step creation until I change the autopopulated queue value

ENTESB-13046

Restore using operator binary not working as expected

ENTESB-13366

Operator instructions unclear and secret create steps are not easy to debug

ENTESB-13966

Discovery of deployed integration API seems disabled but not really

ENTESB-14552

support for multicast queue

ENTESB-17394

Error exclamation marks doesn’t show error message

ENTESB-17404

Build leveldb-jni for x86

ENTESB-17888

validation error when connecting to an https endpoint

ENTESB-18042

Failed to watch errors printed in the operator logs

ENTESB-18364

Hawtio - CSP issues when using Hawtio with Keycloak

ENTESB-19351

FIPS on OCP - Jolokia agent doesn’t start due to unsupported security encoding

ENTESB-19352

FIPS on OCP - karaf-maven-plugin assembly goal fails to unsupported security provider

ENTESB-19745

Quickstart spring-boot-camel-amq integrations tests references old AMQ Broker version

ENTESB-19757

Provide a source container image for apicurito

ENTESB-19956

[Syndesis] CVE-2022-24785 Moment.js: Path traversal in moment.locale [fuse-7]

ENTESB-19986

Fuse hawtio includes HTTPClient 3.1 - CVE-2012-5783

ENTESB-20096

AMQ6 image - V2 schema 1 manifest digest are no longer supported for image pulls

ENTESB-20175

Missing dataformats fhir-json/fhir-xml/xml-json in runtime specific catalogs

ENTESB-20177

Send correct UMB messages for container builds

ENTESB-20404

Camel http4 producer encodes array data to the http uri parameter as comma separated instead of multi-values parameters

ENTESB-20485

CVE-2022-42920 apache-bcel: Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing [fuse-7]

ENTESB-20595

Backport request for ENTMQCL-2977 to Fuse 7.11.x

ENTESB-20596

CVE-2022-41940 engine.io: Specially crafted HTTP request can trigger an uncaught exception [fuse-7]

ENTESB-20598

Incomplete fix of CVE-2020-13956

ENTESB-20618

CVE-2022-41881 codec-haproxy: HAProxyMessageDecoder Stack Exhaustion DoS [fuse-7]

ENTESB-20619

CVE-2022-41854 dev-java-snakeyaml: dev-java/snakeyaml: DoS via stack overflow [fuse-7]

ENTESB-20626

CVE-2022-40146 batik: Server-Side Request Forgery (SSRF) vulnerability [fuse-7]

ENTESB-20627

CVE-2022-38398 batik: Server-Side Request Forgery [fuse-7]

ENTESB-20628

CVE-2022-38648 batik: Server-Side Request Forgery [fuse-7]

ENTESB-20630

CVE-2022-46364 CXF: Apache CXF: SSRF Vulnerability [fuse-7]

ENTESB-20632

CVE-2022-46363 CXF: Apache CXF: directory listing / code exfiltration [fuse-7]

ENTESB-20637

CVE-2022-4492 undertow: Server identity in https connection is not checked by the undertow client [fuse-7]

ENTESB-20641

CVE-2022-41946 jdbc-postgresql: postgresql-jdbc: Information leak of prepared statement data due to insecure temporary file permissions [fuse-7]

ENTESB-20663

Errors during Karaf startup with jdk17

ENTESB-20664

Errors during EAP startup with jdk17

ENTESB-20672

CVE-2022-45143 tomcat: JsonErrorReportValve injection [fuse-7]

ENTESB-20690

CVE-2022-36437 hazelcast: Hazelcast connection caching [fuse-7]

ENTESB-20693

Review patch-maven-plugin karaf-maven-plugin communication

ENTESB-20696

A custom fuse console route doesn’t work.

ENTESB-20697

AutomaticRecovery from RabbitMQ Connection Factory is always creating a new connection

ENTESB-20701

fuse-patch may incorrectly report that a patch has already been applied

ENTESB-20702

netty4-http forwards a bad response (exception + http code 200)

ENTESB-20710

CXF test errors after upgrading to Karaf 4.4 and Pax Web 8

ENTESB-20711

Any issue with camel-aws 2.23 component with TLS 1.3 in Fuse 7.11 ?

ENTESB-20712

Camel test errors after upgrading to Karaf 4.4 and Pax Web 8

ENTESB-20720

Multicast not returning aggregated

ENTESB-20726

Hazelcast upgrade seems to break JCache Integration

ENTESB-20741

Wrong javax/mail/mail version used in fuse projects.

ENTESB-20742

Wrong log4j-slf4j18-impl version is used fuse projects.

ENTESB-20754

[Hawtio] Can’t login in Karaf

ENTESB-20826

CVE-2022-41966 xstream: Denial of Service by injecting recursive collections or maps based on element’s hash values raising a stack overflow [fuse-7]

ENTESB-20828

cxf - server transport isn’t up properly

ENTESB-20829

[Karaf] JCE cannot authenticate the provider BC

ENTESB-20831

Use groupified API versions in json files

ENTESB-20835

Karaf pax web - OPTIONS methods not exposed

ENTESB-20836

Hibernate fuse version clashes with spring boot

ENTESB-20839

[Karaf] JMX ACL MBean authentification problem

ENTESB-20840

[Karaf] 10 features cannot be installed

ENTESB-20841

Fuse archetype Spring Boot properties in SB1 format

ENTESB-20842

camel-master component is unable to load cluster service

ENTESB-20845

CVE-2023-1108 undertow: Infinite loop in SslConduit during close [fuse-7]

ENTESB-20847

[Karaf] Jasypt encryption problem JDK 17 and RHEL8-FIPS

ENTESB-20850

[Standalone] No response messages via fuse client

ENTESB-20851

[Standalone] Colorised commands in history

ENTESB-20853

[Fuse on Openshift] - Wrong Docker image reference in Quickstarts

ENTESB-20854

[Fuse on Openshift] - Application templates - No tag "1.12" with image streams in fis-image-streams.json

ENTESB-20855

[Fuse on Openshift] - Wrong WILDFLY version in EAP images JDK8/11

ENTESB-20857

[Fuse on Openshift] - Application templates - Templates filled with old 7.11 references

ENTESB-20859

[Patching] Unable to patch 7.11 to 7.12

ENTESB-20862

[karaf FoO] unable to use client into the POD

ENTESB-20869

CVE-2023-20860 springframework: Security Bypass With Un-Prefixed Double Wildcard Pattern [fuse-7]

ENTESB-20870

CVE-2023-20861 springframework: Spring Expression DoS Vulnerability [fuse-7]

ENTESB-20871

Camel 2.23 tests do not support jdk17

ENTESB-20872

Wildfly Camel 5.10 tests do not support jdk17

ENTESB-20873

CXF 3.3.6 tests do not support jdk17

ENTESB-20950

[Karaf] Doesn’t install features

ENTESB-20951

Camel Mail Component doesn’t use host/port information from session URI parameter

ENTESB-20956

CVE-2022-4492, ensure that Syndesis is using fixed undertow

ENTESB-20957

CVE-2023-1108 undertow: Infinite loop in SslConduit during close (fuse online)

ENTESB-20958

CVE-2022-41704 batik: Apache XML Graphics Batik vulnerable to code execution via SVG [fuse-7]

ENTESB-20959

CVE-2022-42890 batik: Untrusted code execution in Apache XML Graphics Batik [fuse-7]

ENTESB-20960

CVE-2023-22602 shiro-core: shiro: Authentication bypass through a specially crafted HTTP request [fuse-7]

ENTESB-20961

[Fuse On Openshift] QS spring-boot-camel-amq contains a removed image

ENTESB-20963

[Fuse On Openshift] QS Spring-Boot Camel Rest SQL reports wrong deployment step in README

ENTESB-20964

[Fuse On Openshift] Adjust Pod metering label rht.prod_ver formatting

ENTESB-20967

[Fuse on Openshift] QS Spring-Boot Camel Config fails on Spring Cloud due to SB upgrade

ENTESB-20966

Unable to install karaf features separately

ENTESB-20968

[Fuse On Openshift] QS Spring-Boot Camel Rest SQL throws bad SQL grammar exception

ENTESB-20969

[Fuse On Openshift] QS Spring-Boot Camel XA throws bad SQL grammar exception on PostGresSQL connection

ENTESB-20971

Hawtio console metrics shows free memory instead of used

ENTESB-21045

Pax-web-jetty features cannot be installed

ENTESB-21046

[Fuse standalone] Exception in log jdk11 and jdk17

ENTESB-21047

CVE-2023-20860, ensure that Syndesis is using fixed springframework

ENTESB-21048

Cannot install CVE patch on top of 7.12

ENTESB-21049

CVE-2022-41854, ensure that Syndesis is using fixed snakeyaml

ENTESB-21050

Remove org.apache.tomcat.embed dependencies from cxf-spring-boot-starter-jaxrs

ENTESB-21051

[Fuse On Openshift] QS Spring-Boot Camel-Drools, unable to create Kie Server

ENTESB-21053

[Fuse on Openshift] QS Spring Boot Camel Singleton, app won’t start

ENTESB-21052

[Fuse on Openshift] - Karaf - Unable to resolve missing rquirement in a cxf-jaxrs application

ENTESB-21056

CVE-2023-20861, ensure that Syndesis is using fixed springframework

ENTESB-21057

CVE-2022-41946, ensure that Syndesis is using fixed jdbc-postgresql

ENTESB-21058

Karaf, some bundle versions are not inline with versions specified in karaf-bom

ENTESB-21059

Memory leak in pax-url-aether

ENTESB-21061

CXF 3.3.6 downstream failures

ENTESB-21704

CVE-2023-20863 springframework: Spring Expression DoS Vulnerability [fuse-7]

ENTESB-21158

Unattended Jolokia Queries Not Working When Keycloak is Integrated for Access Control

ENTESB-21161

[Offliner] Files cannot be downloaded using offliner manifest file

ENTESB-21162

[Offliner] Missing artifacts

ENTESB-21163

Apicurito pods contain metering labels with incorrect values

ENTESB-21168

CVE-2023-1370 json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) [fuse-7]

ENTESB-21272

[Fuse on Openshift] Wrong version in Quickstart BOM

ENTESB-21273

Remove or refactor non-working quickstart spring-boot-camel-soap-rest-bridge

ENTESB-21274

Wildfly camel 5.10.0 downstream failure

ENTESB-21304

[Fuse on Openshift] - Illegal access on java.xml module using Karaf, jaxws and JDK17, because xerces packages are not exposed

ENTESB-21309

[Fuse on Openshift] - In camel-jdbc on Karaf, can’t retrieve a column from the body exchange

ENTESB-21310

Camel-Velocity: Deprecation warnings

ENTESB-21311

SpringFramework caches a missed TypeConverter and user can not clean it

ENTESB-21316

[Fuse On Openshift] - Dismiss/Remove RHOSAK Quickstarts

ENTESB-21319

CVE-2022-31692 spring-security: Authorization rules can be bypassed via forward or include dispatcher types in Spring Security [fuse-7]

ENTESB-21322

Invalid qualifier for Karaf bundle

ENTESB-21332

CVE-2023-20883 spring-boot: Spring Boot Welcome Page DoS Vulnerability [fuse-7]

ENTESB-21335

patch-maven-plugin doesn’t work with Maven 3.9

ENTESB-21412

Missing refs/tags on GitHub

ENTESB-21415

[Fuse Standalone] Camel-chunk feature missing dependency

ENTESB-21417

CXF 3.3.6 downstream failures

ENTESB-21418

CVE-2023-1370, ensure that Syndesis is using fixed json-smart

ENTESB-21419

[Karaf] Jasypt encryption problem JDK 17 and RHEL8-FIPS

ENTESB-21421

Camel health check behaviour change on Spring Boot runtime

8.4. Bugs resolved in Fuse 7.12.1

The following tables list the resolved bugs in Fuse 7.12.1.

Expand
Table 8.3. Fuse 7.12.1 Resolved Bugs
IssueDescription

ENTESB-21742

New Fuse Console deployments don’t work after yearly "openshift-service-serving-signer" certificate rotation.

ENTESB-21757

[JDG-4351][JBMAR-235] camel-infinispan requires jboss-marshalling update from 2.0.9.Final to 2.0.11.Final onwards

ENTESB-21776

Fuse on Openshift image uses very old jmx_prometheus_javaagent.jar

ENTESB-21858

Karaf won’t start when using JDK 11.0.20

ENTESB-21878

NullPointerException when logging is at WARN level

ENTESB-21881

Problem using -Dpatch for patch-maven-plugin with Maven 3.9

ENTESB-22087

Cannot install patch 7.12.1 on top of 7.12

ENTESB-21763

camel-http4 with toD does not work on Karaf

ENTESB-21865

pollEnrich files component behavior change between 6.3 and 7.11

CVE-2023-46604

CVE-2023-46604 activemq-openwire: OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack [fuse-7]

CVE-2023-40167

CVE-2023-40167 jetty-http: jetty: Improper validation of HTTP/1 content-length [fuse-7]

CVE-2023-3223

CVE-2023-3223 undertow: OutOfMemoryError due to @MultipartConfig handling [fuse-7]

CVE-2023-36479

CVE-2023-36479 jetty-servlets: jetty: Improper addition of quotation marks to user inputs in CgiServlet [fuse-7]

CVE-2023-39410

CVE-2023-39410 avro: apache-avro: Apache Avro Java SDK: Memory when deserializing untrusted data in Avro Java SDK [fuse-7]

CVE-2023-34034

CVE-2023-34034 spring-security: spring-security-webflux: path wildcard leads to security bypass [fuse-7]

CVE-2023-44487

CVE-2023-44487 undertow: HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) [fuse-7]

CVE-2023-36478

CVE-2023-36478 http2-hpack: jetty: hpack header values cause denial of service in http/2 [fuse-7]

CVE-2023-41900

CVE-2023-41900 jetty-openid: jetty: OpenId Revoked authentication allows one request [fuse-7]

Back to top
Red Hat logoGithubredditYoutubeTwitter

Learn

Try, buy, & sell

Communities

About Red Hat Documentation

We help Red Hat users innovate and achieve their goals with our products and services with content they can trust. Explore our recent updates.

Making open source more inclusive

Red Hat is committed to replacing problematic language in our code, documentation, and web properties. For more details, see the Red Hat Blog.

About Red Hat

We deliver hardened solutions that make it easier for enterprises to work across platforms and environments, from the core datacenter to the network edge.

Theme

© 2025 Red Hat