Red Hat Security Advisory: Red Hat OpenShift Application Runtimes Thorntail 2.4.0 security & bug fix update
🔗 CVE IDs covered (14)
📋 Description
CVE-2018-1067 — undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) CVE-2018-1114 — undertow: File descriptor leak caused by JarURLConnection.getLastModified() allows attacker to cause a denial of service CVE-2018-10862 — wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip) CVE-2018-10894 — keycloak: auth permitted with expired certs in SAML client CVE-2018-10912 — keycloak: infinite loop in session replacement leading to denial of service CVE-2018-11307 — jackson-databind: Potential information exfiltration with default typing, serialization gadget from MyBatis CVE-2018-12022 — jackson-databind: improper polymorphic deserialization of types from Jodd-db library CVE-2018-12023 — jackson-databind: improper polymorphic deserialization of types from Oracle JDBC driver CVE-2018-14718 — jackson-databind: arbitrary code execution in slf4j-ext class CVE-2018-14719 — jackson-databind: arbitrary code execution in blaze-ds-opt and blaze-ds-core classes CVE-2018-19360 — jackson-databind: improper polymorphic deserialization in axis2-transport-jms class CVE-2018-19361 — jackson-databind: improper polymorphic deserialization in openjpa class CVE-2018-19362 — jackson-databind: improper polymorphic deserialization in jboss-common-core class CVE-2018-1000180 — bouncycastle: flaw in the low-level interface to RSA key pair generator
🎯 Affected products1
- Text-Only RHOAR
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update).
🔗 References (19)
- selfhttps://access.redhat.com/errata/RHSA-2019:0877
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=catRhoar.thorntail&version=2.4.0
- externalhttps://access.redhat.com/documentation/en-us/red_hat_openshift_application_runtimes/1/html-single/rhoar_thorntail_release_notes/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1550671
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1573045
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1588306
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1593527
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1599434
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1607624
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1666415
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1666418
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1666482
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1666484
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1666489
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1671096
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1671097
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1677341
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2019/rhsa-2019_0877.json