RHSA-2020:2561CriticalCVSS 9.8

Red Hat Security Advisory: EAP Continuous Delivery Technical Preview Release 12 security update

Published
June 15, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2017-12174 — artemis/hornetq: memory exhaustion via UDP and JGroups discovery CVE-2017-12196 — undertow: Client can use bogus uri in Digest authentication CVE-2017-12629 — Solr: Code execution via entity expansion CVE-2017-15089 — infinispan: Unsafe deserialization of malicious object injected into data cache CVE-2018-8088 — slf4j: Deserialisation vulnerability in EventData constructor can allow for arbitrary code execution

🎯 Affected products1

  • Red Hat JBoss Enterprise Application Platform Continuous Delivery

✅ Remediation

Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. You must restart the JBoss server process for the update to take effect. The References section of this erratum contains a download link (you must log in to download the update) Workaround: Until fixes are available, all Solr users are advised to restart their Solr instances with the system parameter `-Ddisable.configEdit=true`. This will disallow any changes to be made to configurations via the Config API. This is a key factor in this vulnerability, since it allows GET requests to add the RunExecutableListener to the config. This is sufficient to protect from this type of attack, but means you cannot use the edit capabilities of the Config API until further fixes are in place.

🔗 References (8)