RHSA-2020:0727HighCVSS 9.8

Red Hat Security Advisory: Red Hat Data Grid 7.3.3 security update

Published
March 5, 2020
Last Modified
August 15, 2026

🔗 CVE IDs covered (12)

📋 Description

CVE-2018-14335 — h2: Information Exposure due to insecure handling of permissions in the backup CVE-2019-3805 — wildfly: Race condition on PID file allows for termination of arbitrary processes by local users CVE-2019-3888 — undertow: leak credentials to log files UndertowLogger.REQUEST_LOGGER.undertowRequestFailed CVE-2019-9512 — HTTP/2: flood using PING frames results in unbounded memory growth CVE-2019-9514 — HTTP/2: flood using HEADERS frames results in unbounded memory growth CVE-2019-9515 — HTTP/2: flood using SETTINGS frames results in unbounded memory growth CVE-2019-9518 — HTTP/2: flood using empty frames results in excessive resource consumption CVE-2019-10173 — xstream: remote code execution due to insecure XML deserialization (regression of CVE-2013-7285) CVE-2019-10174 — infinispan: invokeAccessibly method from ReflectionUtil class allows to invoke private methods CVE-2019-10184 — undertow: Information leak in requests for directories without trailing slashes CVE-2019-10212 — undertow: DEBUG log for io.undertow.request.security if enabled leaks credentials to log files CVE-2019-14379 — jackson-databind: default typing mishandling leading to remote code execution

🎯 Affected products1

  • Red Hat Data Grid 7.3.3

✅ Remediation

To install this update, do the following: 1. Download the Data Grid 7.3.3 server patch from the customer portal. 2. Back up your existing Data Grid installation. You should back up databases, configuration files, and so on. 3. Install the Data Grid 7.3.3 server patch. Refer to the 7.3 Release Notes for patching instructions. 4. Restart Data Grid to ensure the changes take effect. Workaround: There is no known mitigation for this issue. Workaround: Use Elytron instead of legacy Security subsystem. Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS`

🔗 References (17)