Red Hat Security Advisory: EAP XP 1 security update to CVE fixes in the EAP 7.3.x base
🔗 CVE IDs covered (7)
📋 Description
CVE-2020-8908 — guava: local information disclosure via temporary directory created with unsafe permissions CVE-2020-13936 — velocity: arbitrary code execution when attacker is able to modify templates CVE-2020-28052 — bouncycastle: password bypass in OpenBSDBCrypt.checkPassword utility possible CVE-2020-35510 — jboss-remoting: Threads hold up forever in the EJB server by suppressing the ack from an EJB client CVE-2021-20220 — undertow: Possible regression in fix for CVE-2020-10687 CVE-2021-20250 — wildfly: Information disclosure due to publicly accessible privileged actions in JBoss EJB Client CVE-2021-21290 — netty: Information disclosure via the local system temporary directory
🎯 Affected products1
- Red Hat EAP-XP via EAP 7.3.x base
✅ Remediation
This advisory is informational only. There are no code changes associated with it. No action is required. Workaround: Users unable to upgrade to version 1.67 or greater can copy the `OpenBSDBCrypt.doCheckPassword()` method implementation (https://github.com/bcgit/bc-java/blob/r1rv67/core/src/main/java/org/bouncycastle/crypto/generators/OpenBSDBCrypt.java#L259-L343) into their own utility class and supplement it with the required methods and variables as required
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2021:2210
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/articles/5734021
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.3/html-single/installation_guide
- externalhttps://access.redhat.com/articles/5886431
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1905796
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1906919
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1912881
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1923133
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1927028
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1929479
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1937440
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_2210.json