Red Hat Security Advisory: Red Hat JBoss Fuse/A-MQ 6.3 R14 security and bug fix update
🔗 CVE IDs covered (7)
📋 Description
CVE-2019-0201 — zookeeper: Information disclosure in Apache ZooKeeper CVE-2019-9512 — HTTP/2: flood using PING frames results in unbounded memory growth CVE-2019-9514 — HTTP/2: flood using HEADERS frames results in unbounded memory growth CVE-2019-9515 — HTTP/2: flood using SETTINGS frames results in unbounded memory growth CVE-2019-9518 — HTTP/2: flood using empty frames results in excessive resource consumption CVE-2019-10173 — xstream: remote code execution due to insecure XML deserialization (regression of CVE-2013-7285) CVE-2019-12384 — jackson-databind: failure to block the logback-core class from polymorphic deserialization leading to remote code execution
🎯 Affected products1
- Red Hat Fuse 6.3
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Installation instructions are located in the download section of the customer portal. The References section of this erratum contains a download link (you must log in to download the update). Workaround: Use an authentication method other than Digest (e.g. Kerberos) or upgrade to zookeeper 3.4.14 or later (3.5.5 or later if on the 3.5 branch). [https://zookeeper.apache.org/security.html#CVE-2019-0201] Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible: * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS`
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2019:4352
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=jboss.amq.broker&downloadType=securityPatches&version=6.3.0
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=jboss.fuse&downloadType=securityPatches&version=6.3
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_fuse/6.3/html/release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1715197
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1722971
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1725807
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735645
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735744
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735745
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735749
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2019/rhsa-2019_4352.json