Red Hat Security Advisory: Red Hat Fuse 7.5.0 security update
🔗 CVE IDs covered (27)
📋 Description
CVE-2017-15095 — jackson-databind: Unsafe deserialization due to incomplete black list (incomplete fix for CVE-2017-7525) CVE-2017-17485 — jackson-databind: Unsafe deserialization due to incomplete black list (incomplete fix for CVE-2017-15095) CVE-2018-1131 — infinispan: deserialization of data in XML and JSON transcoders CVE-2018-8009 — hadoop: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file CVE-2018-8034 — tomcat: Host name verification missing in WebSocket client CVE-2018-11307 — jackson-databind: Potential information exfiltration with default typing, serialization gadget from MyBatis CVE-2018-11775 — activemq: ActiveMQ Client Missing TLS Hostname Verification CVE-2018-11796 — tika: Incomplete fix allows for XML entity expansion resulting in denial of service CVE-2018-12022 — jackson-databind: improper polymorphic deserialization of types from Jodd-db library CVE-2018-12023 — jackson-databind: improper polymorphic deserialization of types from Oracle JDBC driver CVE-2018-14718 — jackson-databind: arbitrary code execution in slf4j-ext class CVE-2018-14719 — jackson-databind: arbitrary code execution in blaze-ds-opt and blaze-ds-core classes CVE-2018-14720 — jackson-databind: exfiltration/XXE in some JDK classes CVE-2018-14721 — jackson-databind: server-side request forgery (SSRF) in axis2-jaxws class CVE-2018-19360 — jackson-databind: improper polymorphic deserialization in axis2-transport-jms class CVE-2018-19361 — jackson-databind: improper polymorphic deserialization in openjpa class CVE-2018-19362 — jackson-databind: improper polymorphic deserialization in jboss-common-core class CVE-2018-1000850 — retrofit: Directory traversal in RequestBuilder allows manipulation of resources CVE-2019-0201 — zookeeper: Information disclosure in Apache ZooKeeper CVE-2019-0204 — mesos: docker image code execution CVE-2019-9512 — HTTP/2: flood using PING frames results in unbounded memory growth CVE-2019-9514 — HTTP/2: flood using HEADERS frames results in unbounded memory growth CVE-2019-9515 — HTTP/2: flood using SETTINGS frames results in unbounded memory growth CVE-2019-9518 — HTTP/2: flood using empty frames results in excessive resource consumption CVE-2019-10173 — xstream: remote code execution due to insecure XML deserialization (regression of CVE-2013-7285) CVE-2019-14860 — syndesis: default CORS configuration is allow all CVE-2019-16869 — netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers
🎯 Affected products1
- Red Hat Fuse 7.5.0
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Installation instructions are available from the Fuse 7.5.0 product documentation page: https://access.redhat.com/documentation/en-us/red_hat_fuse/7.5/ Workaround: Mitigation to this problem is to not trigger polymorphic desrialization globally by using: objectMapper.enableDefaultTyping() and rather use @JsonTypeInfo on the class property to explicitly define the type information. For more information on this issue please refer to https://www.github.com/mbechler/marshalsec/blob/master/marshalsec.pdf?raw=true Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS` Workaround: Use an authentication method other than Digest (e.g. Kerberos) or upgrade to zookeeper 3.4.14 or later (3.5.5 or later if on the 3.5 branch). [https://zookeeper.apache.org/security.html#CVE-2019-0201] Workaround: * Use HTTP/2 instead (clear boundaries between requests) * Disable reuse of backend connections eg. ```http-reuse never``` in HAProxy or whatever equivalent LB settings
🔗 References (32)
- selfhttps://access.redhat.com/errata/RHSA-2019:3892
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.fuse&version=7.5.0
- externalhttps://access.redhat.com/documentation/en-us/red_hat_fuse/7.5/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1506612
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1528565
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1576492
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1593018
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1607580
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1629083
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1639090
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1663904
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1666415
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1666418
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1666423
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1666428
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1666482
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1666484
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1666489
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1671096
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1671097
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1677341
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1692755
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1715197
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1722971
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735645
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735744
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735745
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735749
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1758619
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1761912
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2019/rhsa-2019_3892.json