Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.2.4 security update
🔗 CVE IDs covered (8)
📋 Description
CVE-2019-10184 — undertow: Information leak in requests for directories without trailing slashes CVE-2019-10202 — codehaus: incomplete fix for unsafe deserialization in jackson-databind vulnerabilities CVE-2019-10212 — undertow: DEBUG log for io.undertow.request.security if enabled leaks credentials to log files CVE-2019-12086 — jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files on the server. CVE-2019-12384 — jackson-databind: failure to block the logback-core class from polymorphic deserialization leading to remote code execution CVE-2019-12814 — jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files on the server via crafted JSON message. CVE-2019-14379 — jackson-databind: default typing mishandling leading to remote code execution CVE-2019-19343 — Undertow: Memory Leak in Undertow HttpOpenListener due to holding remoting connections indefinitely
🎯 Affected products1
- Red Hat JBoss EAP 7.2
✅ Remediation
Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. The References section of this erratum contains a download link (you must log in to download the update). The JBoss server process must be restarted for the update to take effect. Workaround: Use Elytron instead of legacy Security subsystem. Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS` Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible: * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS` Workaround: This vulnerability relies on jdom (org.jdom) or jdom2 (org.jdom2) being present in the application's ClassPath. Applications using jackson-databind that do not also use jdom or jdom2 are not impacted by this vulnerability. Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS`
🔗 References (39)
- selfhttps://access.redhat.com/errata/RHSA-2019:2938
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=appplatform&downloadType=securityPatches&version=7.2
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.2/
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.2/html-single/installation_guide/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1713068
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1713468
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1725795
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1725807
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1731271
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1731984
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1737517
- externalhttps://issues.redhat.com/browse/JBEAP-16455
- externalhttps://issues.redhat.com/browse/JBEAP-16779
- externalhttps://issues.redhat.com/browse/JBEAP-17045
- externalhttps://issues.redhat.com/browse/JBEAP-17062
- externalhttps://issues.redhat.com/browse/JBEAP-17073
- externalhttps://issues.redhat.com/browse/JBEAP-17109
- externalhttps://issues.redhat.com/browse/JBEAP-17112
- externalhttps://issues.redhat.com/browse/JBEAP-17162
- externalhttps://issues.redhat.com/browse/JBEAP-17178
- externalhttps://issues.redhat.com/browse/JBEAP-17182
- externalhttps://issues.redhat.com/browse/JBEAP-17183
- externalhttps://issues.redhat.com/browse/JBEAP-17223
- externalhttps://issues.redhat.com/browse/JBEAP-17238
- externalhttps://issues.redhat.com/browse/JBEAP-17250
- externalhttps://issues.redhat.com/browse/JBEAP-17271
- externalhttps://issues.redhat.com/browse/JBEAP-17273
- externalhttps://issues.redhat.com/browse/JBEAP-17274
- externalhttps://issues.redhat.com/browse/JBEAP-17276
- externalhttps://issues.redhat.com/browse/JBEAP-17277
- externalhttps://issues.redhat.com/browse/JBEAP-17278
- externalhttps://issues.redhat.com/browse/JBEAP-17294
- externalhttps://issues.redhat.com/browse/JBEAP-17311
- externalhttps://issues.redhat.com/browse/JBEAP-17320
- externalhttps://issues.redhat.com/browse/JBEAP-17321
- externalhttps://issues.redhat.com/browse/JBEAP-17334
- externalhttps://issues.redhat.com/browse/JBEAP-17527
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2019/rhsa-2019_2938.json