RHSA-2019:0877HighCVSS 8.1

Red Hat Security Advisory: Red Hat OpenShift Application Runtimes Thorntail 2.4.0 security & bug fix update

Published
April 24, 2019
Last Modified
August 4, 2026

🔗 CVE IDs covered (14)

📋 Description

CVE-2018-1067 — undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) CVE-2018-1114 — undertow: File descriptor leak caused by JarURLConnection.getLastModified() allows attacker to cause a denial of service CVE-2018-10862 — wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip) CVE-2018-10894 — keycloak: auth permitted with expired certs in SAML client CVE-2018-10912 — keycloak: infinite loop in session replacement leading to denial of service CVE-2018-11307 — jackson-databind: Potential information exfiltration with default typing, serialization gadget from MyBatis CVE-2018-12022 — jackson-databind: improper polymorphic deserialization of types from Jodd-db library CVE-2018-12023 — jackson-databind: improper polymorphic deserialization of types from Oracle JDBC driver CVE-2018-14718 — jackson-databind: arbitrary code execution in slf4j-ext class CVE-2018-14719 — jackson-databind: arbitrary code execution in blaze-ds-opt and blaze-ds-core classes CVE-2018-19360 — jackson-databind: improper polymorphic deserialization in axis2-transport-jms class CVE-2018-19361 — jackson-databind: improper polymorphic deserialization in openjpa class CVE-2018-19362 — jackson-databind: improper polymorphic deserialization in jboss-common-core class CVE-2018-1000180 — bouncycastle: flaw in the low-level interface to RSA key pair generator

🎯 Affected products1

  • Text-Only RHOAR

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update).

🔗 References (19)