Red Hat Security Advisory: Red Hat support for Spring Boot 2.2.6.SP2 security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2020-10688 — RESTEasy: RESTEASY003870 exception in RESTEasy can lead to a reflected XSS attack CVE-2020-10693 — hibernate-validator: Improper input validation in the interpolation of constraint error messages CVE-2020-13934 — tomcat: OutOfMemoryException caused by HTTP/2 connection leak could lead to DoS CVE-2020-13935 — tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoS
🎯 Affected products1
- Red Hat Runtimes Spring Boot 2.2.6
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). Workaround: You can pass user input as an expression variable by unwrapping the context to HibernateConstraintValidatorContext. Please refer to the https://in.relation.to/2020/05/07/hibernate-validator-615-6020-released/ and https://docs.jboss.org/hibernate/stable/validator/reference/en-US/html_single/#_the_code_constraintvalidatorcontext_code. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2020:3806
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=catRhoar.spring.boot&version=2.2.6.SP2
- externalhttps://access.redhat.com/documentation/en-us/red_hat_support_for_spring_boot/2.2/html-single/release_notes_for_spring_boot_2.2/index#advisories-related-to-current-release-spring-boot
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1805501
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1814974
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1857024
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1857040
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_3806.json