Red Hat Security Advisory: Red Hat Data Grid 7.3.2 security update
🔗 CVE IDs covered (11)
📋 Description
CVE-2018-11307 — jackson-databind: Potential information exfiltration with default typing, serialization gadget from MyBatis CVE-2018-12022 — jackson-databind: improper polymorphic deserialization of types from Jodd-db library CVE-2018-12023 — jackson-databind: improper polymorphic deserialization of types from Oracle JDBC driver CVE-2018-14718 — jackson-databind: arbitrary code execution in slf4j-ext class CVE-2018-14719 — jackson-databind: arbitrary code execution in blaze-ds-opt and blaze-ds-core classes CVE-2018-14720 — jackson-databind: exfiltration/XXE in some JDK classes CVE-2018-14721 — jackson-databind: server-side request forgery (SSRF) in axis2-jaxws class CVE-2018-19360 — jackson-databind: improper polymorphic deserialization in axis2-transport-jms class CVE-2018-19361 — jackson-databind: improper polymorphic deserialization in openjpa class CVE-2018-19362 — jackson-databind: improper polymorphic deserialization in jboss-common-core class CVE-2019-10158 — infinispan: Session fixation protection broken for Spring Session integration
🎯 Affected products1
- Red Hat Data Grid
✅ Remediation
To install this update, do the following: 1. Download the Data Grid 7.3.2 server patch from the customer portal. 2. Back up your existing Data Grid installation. You should back up databases, configuration files, and so on. 3. Install the Data Grid 7.3.2 server patch. Refer to the 7.3 Release Notes for patching instructions. 4. Restart Data Grid to ensure the changes take effect. Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS`
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2019:4037
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/softwareDetail.html?softwareId=70381&product=data.grid&version=7.3&downloadType=patches
- externalhttps://access.redhat.com/documentation/en-us/red_hat_data_grid/7.3/html-single/red_hat_data_grid_7.3_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1666415
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1666418
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1666423
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1666428
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1666482
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1666484
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1666489
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1671096
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1671097
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1677341
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1714359
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2019/rhsa-2019_4037.json