Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.2.5 security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2019-9511 — HTTP/2: large amount of data requests leads to denial of service CVE-2019-9512 — HTTP/2: flood using PING frames results in unbounded memory growth CVE-2019-9514 — HTTP/2: flood using HEADERS frames results in unbounded memory growth CVE-2019-9515 — HTTP/2: flood using SETTINGS frames results in unbounded memory growth CVE-2019-14838 — wildfly-core: Incorrect privileges for 'Monitor', 'Auditor' and 'Deployer' user by default CVE-2019-14843 — wildfly-security-manager: security manager authorization bypass
🎯 Affected products1
- Red Hat JBoss EAP 7.2
✅ Remediation
Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. The References section of this erratum contains a download link (you must log in to download the update). The JBoss server process must be restarted for the update to take effect. Workaround: Red Hat Quay 3.0 uses Nginx 1.12 from Red Hat Software Collections. It will be updated once a fixed is released for Software Collections. In the meantime users of Quay can disable http/2 support in Nginx by following these instructions: 1. Copy the Nginx configuration from the quay container to the host $ docker cp 3aadf1421ba3:/quay-registry/conf/nginx/ /mnt/quay/nginx 2. Edit the Nginx configuration, removing http/2 support $ sed -i 's/http2 //g' /mnt/quay/nginx/nginx.conf 3. Restart Nginx with the new configuration mounted into the container, eg: $ docker run --restart=always -p 443:8443 -p 80:8080 --sysctl net.core.somaxconn=4096 -v /mnt/quay/config:/conf/stack:Z -v /mnt/quay/storage:/datastorage -v /mnt/quay/nginx:/quay-registry/config/nginx:Z -d quay.io/redhat/quay:v3.0.3 Workaround: This flaw only affects the Security Manager running under JDK 11 or 8. To mitigate exposure to this flaw, do not run under those JDK versions.
🔗 References (34)
- selfhttps://access.redhat.com/errata/RHSA-2019:4021
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=appplatform&downloadType=securityPatches&version=7.2
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.2/
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.2/html-single/installation_guide/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735645
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735744
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735745
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1741860
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1751227
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1752980
- externalhttps://issues.redhat.com/browse/JBEAP-17075
- externalhttps://issues.redhat.com/browse/JBEAP-17220
- externalhttps://issues.redhat.com/browse/JBEAP-17365
- externalhttps://issues.redhat.com/browse/JBEAP-17476
- externalhttps://issues.redhat.com/browse/JBEAP-17478
- externalhttps://issues.redhat.com/browse/JBEAP-17483
- externalhttps://issues.redhat.com/browse/JBEAP-17495
- externalhttps://issues.redhat.com/browse/JBEAP-17496
- externalhttps://issues.redhat.com/browse/JBEAP-17513
- externalhttps://issues.redhat.com/browse/JBEAP-17521
- externalhttps://issues.redhat.com/browse/JBEAP-17523
- externalhttps://issues.redhat.com/browse/JBEAP-17547
- externalhttps://issues.redhat.com/browse/JBEAP-17548
- externalhttps://issues.redhat.com/browse/JBEAP-17560
- externalhttps://issues.redhat.com/browse/JBEAP-17579
- externalhttps://issues.redhat.com/browse/JBEAP-17582
- externalhttps://issues.redhat.com/browse/JBEAP-17631
- externalhttps://issues.redhat.com/browse/JBEAP-17647
- externalhttps://issues.redhat.com/browse/JBEAP-17665
- externalhttps://issues.redhat.com/browse/JBEAP-17722
- externalhttps://issues.redhat.com/browse/JBEAP-17874
- externalhttps://issues.redhat.com/browse/JBEAP-17880
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2019/rhsa-2019_4021.json