Red Hat Security Advisory: EAP Continuous Delivery Technical Preview Release 13 security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2017-12196 — undertow: Client can use bogus uri in Digest authentication CVE-2018-1067 — undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) CVE-2018-7489 — jackson-databind: incomplete fix for CVE-2017-7525 permits unsafe serialization via c3p0 libraries CVE-2018-10237 — guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of service CVE-2018-10862 — wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip)
🎯 Affected products1
- Red Hat JBoss Enterprise Application Platform Continuous Delivery
✅ Remediation
Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. You must restart the JBoss server process for the update to take effect. The References section of this erratum contains a download link (you must log in to download the update) Workaround: Advice on how to remain safe while using JAX-RS webservices on JBoss EAP 7.x is available here: https://access.redhat.com/solutions/3279231 https://github.com/FasterXML/jackson-docs/wiki/JacksonPolymorphicDeserialization General Mitigation: Try to avoid * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS`
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2020:2562
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1503055
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1549276
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1550671
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1573391
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1593527
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_2562.json