RHSA-2020:3017HighCVSS 7.5

Red Hat Security Advisory: Red Hat support for Spring Boot 2.1.15 security and bug fix update

Published
July 27, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2020-1714 — keycloak: Lack of checks in ObjectInputStream leading to Remote Code Execution CVE-2020-9484 — tomcat: deserialization flaw in session persistence storage leading to RCE

🎯 Affected products1

  • Red Hat Runtimes Spring Boot 2.1.15

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). Workaround: There is currently no known mitigation for this issue. Workaround: Users may configure the PersistenceManager with an appropriate value for sessionAttributeValueClassNameFilter to ensure that only application provided attributes are serialized and deserialized. For more details about the configuration, refer to the Apache Tomcat 9 Configuration Reference https://tomcat.apache.org/tomcat-9.0-doc/config/manager.html.

🔗 References (7)