RHSA-2020:2367HighCVSS 7.6

Red Hat Security Advisory: Red Hat support for Spring Boot 2.1.13 security and bug fix update

Published
June 4, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2019-14888 — undertow: possible Denial Of Service (DOS) in Undertow HTTP server listening on HTTPS CVE-2020-1745 — undertow: AJP File Read/Inclusion Vulnerability CVE-2020-1935 — tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling CVE-2020-1938 — tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability

🎯 Affected products1

  • Red Hat Runtimes Spring Boot 2.1.13

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). Workaround: Enable HTTP2 (enable-http2="true") in the undertow's HTTPS settings. Workaround: Please refer to the Red Hat knowledgebase article: https://access.redhat.com/solutions/4851251 Workaround: Workaround for Red Hat Satellite 6 is to add iptables rule to deny TCP requests of Tomcat that are not originating from the Satellite. For other Red Hat products, either mitigation isn't available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (9)