Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.3.1 Security update
🔗 CVE IDs covered (21)
📋 Description
CVE-2018-14371 — mojarra: Path traversal in ResourceManager.java:getLocalePrefix() via the loc parameter CVE-2019-0205 — thrift: Endless loop when feed with specific input data CVE-2019-0210 — thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol CVE-2019-10172 — jackson-mapper-asl: XML external entity similar to CVE-2016-3720 CVE-2019-12423 — cxf: OpenId Connect token service does not properly validate the clientId CVE-2019-14887 — wildfly: The 'enabled-protocols' value in legacy security is not respected if OpenSSL security provider is in use CVE-2019-17573 — cxf: reflected XSS in the services listing page CVE-2020-1695 — resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class CVE-2020-1719 — Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain CVE-2020-1729 — SmallRye: SecuritySupport class is incorrectly public and contains a static method to access the current threads context class loader CVE-2020-1745 — undertow: AJP File Read/Inclusion Vulnerability CVE-2020-1757 — undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass CVE-2020-6950 — Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371 CVE-2020-7226 — cryptacular: excessive memory allocation during a decode operation CVE-2020-8840 — jackson-databind: Lacks certain xbean-reflect/JNDI blocking CVE-2020-9546 — jackson-databind: Serialization gadgets in shaded-hikari-config CVE-2020-9547 — jackson-databind: Serialization gadgets in ibatis-sqlmap CVE-2020-9548 — jackson-databind: Serialization gadgets in anteros-core CVE-2020-10688 — RESTEasy: RESTEASY003870 exception in RESTEasy can lead to a reflected XSS attack CVE-2020-10705 — undertow: Memory exhaustion issue in HttpReadListener via "Expect: 100-continue" header CVE-2020-10719 — undertow: invalid HTTP request with large chunk size
🎯 Affected products1
- Red Hat JBoss EAP 7
✅ Remediation
Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. The References section of this erratum contains a download link (you must log in to download the update). The JBoss server process must be restarted for the update to take effect. Workaround: There is no currently known mitigation for this flaw. Workaround: Avoid using an OpenSSL security provider and instead use the default configuration or regular JSSE provider with 'TLS'. Workaround: Mitigate this flaw by disabling the service listing altogether; via setting the "hide-service-list-page" servlet parameter to "true". Workaround: Please refer to the Red Hat knowledgebase article: https://access.redhat.com/solutions/4851251 Workaround: The issue can be mitigated by configuring UrlPathHelper to ignore the servletPath via setting "alwaysUseFullPath". Workaround: There is currently no known mitigation for this security flaw.
🔗 References (76)
- selfhttps://access.redhat.com/errata/RHSA-2020:2515
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.3/
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.3/html-single/installation_guide/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1607709
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1715075
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1730462
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1752770
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1764607
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1764612
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1772008
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1797006
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1797011
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1801380
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1802444
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1805006
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1807305
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1814974
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1816330
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1816332
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1816337
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1816340
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1828459
- externalhttps://issues.redhat.com/browse/JBEAP-16114
- externalhttps://issues.redhat.com/browse/JBEAP-18060
- externalhttps://issues.redhat.com/browse/JBEAP-18163
- externalhttps://issues.redhat.com/browse/JBEAP-18221
- externalhttps://issues.redhat.com/browse/JBEAP-18240
- externalhttps://issues.redhat.com/browse/JBEAP-18241
- externalhttps://issues.redhat.com/browse/JBEAP-18273
- externalhttps://issues.redhat.com/browse/JBEAP-18277
- externalhttps://issues.redhat.com/browse/JBEAP-18288
- externalhttps://issues.redhat.com/browse/JBEAP-18294
- externalhttps://issues.redhat.com/browse/JBEAP-18302
- externalhttps://issues.redhat.com/browse/JBEAP-18315
- externalhttps://issues.redhat.com/browse/JBEAP-18346
- externalhttps://issues.redhat.com/browse/JBEAP-18352
- externalhttps://issues.redhat.com/browse/JBEAP-18361
- externalhttps://issues.redhat.com/browse/JBEAP-18367
- externalhttps://issues.redhat.com/browse/JBEAP-18393
- externalhttps://issues.redhat.com/browse/JBEAP-18409
- externalhttps://issues.redhat.com/browse/JBEAP-18527
- externalhttps://issues.redhat.com/browse/JBEAP-18528
- externalhttps://issues.redhat.com/browse/JBEAP-18596
- externalhttps://issues.redhat.com/browse/JBEAP-18598
- externalhttps://issues.redhat.com/browse/JBEAP-18640
- externalhttps://issues.redhat.com/browse/JBEAP-18653
- externalhttps://issues.redhat.com/browse/JBEAP-18706
- externalhttps://issues.redhat.com/browse/JBEAP-18770
- externalhttps://issues.redhat.com/browse/JBEAP-18775
- externalhttps://issues.redhat.com/browse/JBEAP-18788
- externalhttps://issues.redhat.com/browse/JBEAP-18790
- externalhttps://issues.redhat.com/browse/JBEAP-18818
- externalhttps://issues.redhat.com/browse/JBEAP-18836
- externalhttps://issues.redhat.com/browse/JBEAP-18850
- externalhttps://issues.redhat.com/browse/JBEAP-18870
- externalhttps://issues.redhat.com/browse/JBEAP-18875
- externalhttps://issues.redhat.com/browse/JBEAP-18876
- externalhttps://issues.redhat.com/browse/JBEAP-18877
- externalhttps://issues.redhat.com/browse/JBEAP-18878
- externalhttps://issues.redhat.com/browse/JBEAP-18879
- externalhttps://issues.redhat.com/browse/JBEAP-18929
- externalhttps://issues.redhat.com/browse/JBEAP-18990
- externalhttps://issues.redhat.com/browse/JBEAP-18991
- externalhttps://issues.redhat.com/browse/JBEAP-19035
- externalhttps://issues.redhat.com/browse/JBEAP-19054
- externalhttps://issues.redhat.com/browse/JBEAP-19066
- externalhttps://issues.redhat.com/browse/JBEAP-19117
- externalhttps://issues.redhat.com/browse/JBEAP-19133
- externalhttps://issues.redhat.com/browse/JBEAP-19156
- externalhttps://issues.redhat.com/browse/JBEAP-19181
- externalhttps://issues.redhat.com/browse/JBEAP-19192
- externalhttps://issues.redhat.com/browse/JBEAP-19232
- externalhttps://issues.redhat.com/browse/JBEAP-19281
- externalhttps://issues.redhat.com/browse/JBEAP-19456
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_2515.json