Red Hat Security Advisory: Red Hat build of Thorntail 2.7.0 security and bug fix update
🔗 CVE IDs covered (18)
📋 Description
CVE-2019-12423 — cxf: OpenId Connect token service does not properly validate the clientId CVE-2019-17573 — cxf: reflected XSS in the services listing page CVE-2020-1695 — resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class CVE-2020-1697 — keycloak: stored XSS in client settings via application links CVE-2020-1698 — keycloak: Password leak by logged exception in HttpMethod class CVE-2020-1714 — keycloak: Lack of checks in ObjectInputStream leading to Remote Code Execution CVE-2020-1718 — keycloak: security issue on reset credential flow CVE-2020-1719 — Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain CVE-2020-1724 — keycloak: problem with privacy after user logout CVE-2020-1727 — keycloak: missing input validation in IDP authorization URLs CVE-2020-1732 — Soteria: security identity corruption across concurrent threads CVE-2020-1744 — keycloak: failedLogin Event not sent to BruteForceProtector when using Post Login Flow with Conditional-OTP CVE-2020-1745 — undertow: AJP File Read/Inclusion Vulnerability CVE-2020-1757 — undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass CVE-2020-6950 — Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371 CVE-2020-10688 — RESTEasy: RESTEASY003870 exception in RESTEasy can lead to a reflected XSS attack CVE-2020-10705 — undertow: Memory exhaustion issue in HttpReadListener via "Expect: 100-continue" header CVE-2020-10719 — undertow: invalid HTTP request with large chunk size
🎯 Affected products1
- Text-Only RHOAR
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link for the update. You must be logged in to download the update. Workaround: Mitigate this flaw by disabling the service listing altogether; via setting the "hide-service-list-page" servlet parameter to "true". Workaround: There is currently no known mitigation for this issue. Workaround: Disable reset credential flow. Workaround: Please refer to the Red Hat knowledgebase article: https://access.redhat.com/solutions/4851251 Workaround: The issue can be mitigated by configuring UrlPathHelper to ignore the servletPath via setting "alwaysUseFullPath". Workaround: There is no currently known mitigation for this flaw. Workaround: There is currently no known mitigation for this security flaw.
🔗 References (23)
- selfhttps://access.redhat.com/errata/RHSA-2020:2905
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=catRhoar.thorntail&version=2.7.0
- externalhttps://access.redhat.com/documentation/en-us/red_hat_build_of_thorntail/2.7/html/release_notes_for_thorntail_2.7/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1705975
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1730462
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1752770
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1790292
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1791538
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1796617
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1796756
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1797006
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1797011
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1800527
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1800573
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1801726
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1803241
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1805006
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1805792
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1807305
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1814974
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1828459
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_2905.json