RHSA-2018:2938MediumCVSS 8.6

Red Hat Security Advisory: Red Hat OpenShift Application Runtimes Thorntail 2.2.0 security & bug fix update

Published
October 17, 2018
Last Modified
August 4, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2018-1047 — undertow: Path traversal in ServletResourceManager class CVE-2018-7489 — jackson-databind: incomplete fix for CVE-2017-7525 permits unsafe serialization via c3p0 libraries

🎯 Affected products1

  • Text-Only RHOAR

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). Workaround: Advice on how to remain safe while using JAX-RS webservices on JBoss EAP 7.x is available here: https://access.redhat.com/solutions/3279231 https://github.com/FasterXML/jackson-docs/wiki/JacksonPolymorphicDeserialization General Mitigation: Try to avoid * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS`

🔗 References (7)