RHSA-2020:2561CriticalCVSS 9.8
Red Hat Security Advisory: EAP Continuous Delivery Technical Preview Release 12 security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2017-12174 — artemis/hornetq: memory exhaustion via UDP and JGroups discovery CVE-2017-12196 — undertow: Client can use bogus uri in Digest authentication CVE-2017-12629 — Solr: Code execution via entity expansion CVE-2017-15089 — infinispan: Unsafe deserialization of malicious object injected into data cache CVE-2018-8088 — slf4j: Deserialisation vulnerability in EventData constructor can allow for arbitrary code execution
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2020:2561
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1498378
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1501529
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1503055
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1503610
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1548909
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_2561.json