Red Hat Security Advisory: Red Hat Fuse 7.2 security update
🔗 CVE IDs covered (12)
📋 Description
CVE-2016-5002 — xmlrpc: XML external entity vulnerability SSRF via a crafted DTD CVE-2016-5003 — xmlrpc: Deserialization of untrusted Java object through ex:serializable tag CVE-2017-12196 — undertow: Client can use bogus uri in Digest authentication CVE-2018-1257 — spring-framework: ReDoS Attack with spring-messaging CVE-2018-1259 — spring-data-commons: XXE with Spring Data’s XMLBeam integration CVE-2018-1288 — kafka: Users can perform Broker actions via crafted fetch requests, interfering with data replication and causing data lass CVE-2018-1336 — tomcat: A bug in the UTF-8 decoder can lead to DoS CVE-2018-8014 — tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins CVE-2018-8018 — ignite: Improper deserialization allows for code execution via GridClientJdkMarshaller endpoint CVE-2018-8039 — apache-cxf: TLS hostname verification does not work correctly with com.sun.net.ssl.* CVE-2018-8041 — camel-mail: path traversal vulnerability CVE-2018-12537 — vertx: Improper neutralization of CRLF sequences allows remote attackers to inject arbitrary HTTP response headers
🔗 References (18)
- selfhttps://access.redhat.com/errata/RHSA-2018:3768
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=jboss.fuse&downloadType=distributions&version=7.2.0
- externalhttps://access.redhat.com/documentation/en-us/red_hat_fuse/7.2/
- externalhttps://access.redhat.com/articles/2939351
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1503055
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1508110
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1508123
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1578578
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1578902
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1579611
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1591072
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1595332
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1607591
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1607731
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1611059
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1612644
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2018/rhsa-2018_3768.json