Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.2.8 security update
🔗 CVE IDs covered (11)
📋 Description
CVE-2019-10172 — jackson-mapper-asl: XML external entity similar to CVE-2016-3720 CVE-2019-12423 — cxf: OpenId Connect token service does not properly validate the clientId CVE-2019-17573 — cxf: reflected XSS in the services listing page CVE-2020-1719 — Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain CVE-2020-1729 — SmallRye: SecuritySupport class is incorrectly public and contains a static method to access the current threads context class loader CVE-2020-1732 — Soteria: security identity corruption across concurrent threads CVE-2020-1745 — undertow: AJP File Read/Inclusion Vulnerability CVE-2020-1757 — undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass CVE-2020-7226 — cryptacular: excessive memory allocation during a decode operation CVE-2020-10705 — undertow: Memory exhaustion issue in HttpReadListener via "Expect: 100-continue" header CVE-2020-10719 — undertow: invalid HTTP request with large chunk size
🎯 Affected products1
- Red Hat JBoss EAP 7.2
✅ Remediation
Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. The References section of this erratum contains a download link (you must log in to download the update). The JBoss server process must be restarted for the update to take effect. Workaround: Mitigate this flaw by disabling the service listing altogether; via setting the "hide-service-list-page" servlet parameter to "true". Workaround: Please refer to the Red Hat knowledgebase article: https://access.redhat.com/solutions/4851251 Workaround: The issue can be mitigated by configuring UrlPathHelper to ignore the servletPath via setting "alwaysUseFullPath". Workaround: There is currently no known mitigation for this security flaw.
🔗 References (45)
- selfhttps://access.redhat.com/errata/RHSA-2020:2061
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=appplatform&downloadType=securityPatches&version=7.2
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.2/
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.2/html-single/installation_guide/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1715075
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1752770
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1796617
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1797006
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1797011
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1801380
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1801726
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1802444
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1803241
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1807305
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1828459
- externalhttps://issues.redhat.com/browse/JBEAP-18071
- externalhttps://issues.redhat.com/browse/JBEAP-18267
- externalhttps://issues.redhat.com/browse/JBEAP-18278
- externalhttps://issues.redhat.com/browse/JBEAP-18423
- externalhttps://issues.redhat.com/browse/JBEAP-18438
- externalhttps://issues.redhat.com/browse/JBEAP-18503
- externalhttps://issues.redhat.com/browse/JBEAP-18506
- externalhttps://issues.redhat.com/browse/JBEAP-18536
- externalhttps://issues.redhat.com/browse/JBEAP-18595
- externalhttps://issues.redhat.com/browse/JBEAP-18616
- externalhttps://issues.redhat.com/browse/JBEAP-18628
- externalhttps://issues.redhat.com/browse/JBEAP-18631
- externalhttps://issues.redhat.com/browse/JBEAP-18639
- externalhttps://issues.redhat.com/browse/JBEAP-18646
- externalhttps://issues.redhat.com/browse/JBEAP-18652
- externalhttps://issues.redhat.com/browse/JBEAP-18664
- externalhttps://issues.redhat.com/browse/JBEAP-18724
- externalhttps://issues.redhat.com/browse/JBEAP-18729
- externalhttps://issues.redhat.com/browse/JBEAP-18787
- externalhttps://issues.redhat.com/browse/JBEAP-18789
- externalhttps://issues.redhat.com/browse/JBEAP-18817
- externalhttps://issues.redhat.com/browse/JBEAP-18827
- externalhttps://issues.redhat.com/browse/JBEAP-18835
- externalhttps://issues.redhat.com/browse/JBEAP-18931
- externalhttps://issues.redhat.com/browse/JBEAP-18988
- externalhttps://issues.redhat.com/browse/JBEAP-18989
- externalhttps://issues.redhat.com/browse/JBEAP-19233
- externalhttps://issues.redhat.com/browse/JBEAP-19234
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_2061.json