Red Hat Security Advisory: Red Hat Fuse 7.3.1 security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2016-2510 — bsh2: remote code execution via deserialization CVE-2017-5645 — log4j: Socket receiver deserialization vulnerability CVE-2017-15691 — uima: XML external entity expansion (XXE) can allow attackers to execute arbitrary code CVE-2018-3258 — mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2018) CVE-2018-11798 — thrift: Improper Access Control grants access to files outside the webservers docroot path CVE-2019-17571 — log4j: deserialization of untrusted data in SocketServer
🎯 Affected products1
- Red Hat Fuse 7.3.1
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Installation instructions are available from the Fuse 7.3.0 product documentation page: https://access.redhat.com/documentation/en-us/red_hat_fuse/7.3/ Workaround: Please note that the Log4j upstream strongly recommends against using the SerializedLayout with the SocketAppenders. Customers may mitigate this issue by removing the SocketServer class outright; or if they must continue to use SocketAppenders, they can modify their SocketAppender configuration from SerializedLayout to use JsonLayout instead. An example of this in log4j-server.properties might look like this: log4j.appender.file.layout=org.apache.log4j.JsonLayout
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2019:1545
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.fuse&version=7.3.1
- externalhttps://access.redhat.com/documentation/en-us/red_hat_fuse/7.3
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1310647
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1443635
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1572463
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1640615
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1667188
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2019/rhsa-2019_1545.json