RHSA-2020:2061HighCVSS 8.1

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.2.8 security update

Published
May 11, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (11)

📋 Description

CVE-2019-10172 — jackson-mapper-asl: XML external entity similar to CVE-2016-3720 CVE-2019-12423 — cxf: OpenId Connect token service does not properly validate the clientId CVE-2019-17573 — cxf: reflected XSS in the services listing page CVE-2020-1719 — Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain CVE-2020-1729 — SmallRye: SecuritySupport class is incorrectly public and contains a static method to access the current threads context class loader CVE-2020-1732 — Soteria: security identity corruption across concurrent threads CVE-2020-1745 — undertow: AJP File Read/Inclusion Vulnerability CVE-2020-1757 — undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass CVE-2020-7226 — cryptacular: excessive memory allocation during a decode operation CVE-2020-10705 — undertow: Memory exhaustion issue in HttpReadListener via "Expect: 100-continue" header CVE-2020-10719 — undertow: invalid HTTP request with large chunk size

🎯 Affected products1

  • Red Hat JBoss EAP 7.2

✅ Remediation

Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. The References section of this erratum contains a download link (you must log in to download the update). The JBoss server process must be restarted for the update to take effect. Workaround: Mitigate this flaw by disabling the service listing altogether; via setting the "hide-service-list-page" servlet parameter to "true". Workaround: Please refer to the Red Hat knowledgebase article: https://access.redhat.com/solutions/4851251 Workaround: The issue can be mitigated by configuring UrlPathHelper to ignore the servletPath via setting "alwaysUseFullPath". Workaround: There is currently no known mitigation for this security flaw.

🔗 References (45)