RHSA-2020:2562HighCVSS 8.1

Red Hat Security Advisory: EAP Continuous Delivery Technical Preview Release 13 security update

Published
June 15, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2017-12196 — undertow: Client can use bogus uri in Digest authentication CVE-2018-1067 — undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) CVE-2018-7489 — jackson-databind: incomplete fix for CVE-2017-7525 permits unsafe serialization via c3p0 libraries CVE-2018-10237 — guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of service CVE-2018-10862 — wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip)

🎯 Affected products1

  • Red Hat JBoss Enterprise Application Platform Continuous Delivery

✅ Remediation

Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. You must restart the JBoss server process for the update to take effect. The References section of this erratum contains a download link (you must log in to download the update) Workaround: Advice on how to remain safe while using JAX-RS webservices on JBoss EAP 7.x is available here: https://access.redhat.com/solutions/3279231 https://github.com/FasterXML/jackson-docs/wiki/JacksonPolymorphicDeserialization General Mitigation: Try to avoid * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS`

🔗 References (8)