Red Hat Security Advisory: EAP XP 2 security update to CVE fixes in the EAP 7.3.x base
🔗 CVE IDs covered (9)
📋 Description
CVE-2020-13936 — velocity: arbitrary code execution when attacker is able to modify templates CVE-2020-15522 — bouncycastle: Timing issue within the EC math library CVE-2020-28052 — bouncycastle: password bypass in OpenBSDBCrypt.checkPassword utility possible CVE-2021-3536 — wildfly: XSS via admin console when creating roles in domain mode CVE-2021-20220 — undertow: Possible regression in fix for CVE-2020-10687 CVE-2021-20250 — wildfly: Information disclosure due to publicly accessible privileged actions in JBoss EJB Client CVE-2021-21290 — netty: Information disclosure via the local system temporary directory CVE-2021-21295 — netty: possible request smuggling in HTTP/2 due missing validation CVE-2021-21409 — netty: Request smuggling via content-length header
🎯 Affected products1
- Red Hat EAP-XP 2.0.0 via EAP 7.3.x base
✅ Remediation
This advisory is informational only. There are no code changes associated with it. No action is required. Workaround: Users unable to upgrade to version 1.67 or greater can copy the `OpenBSDBCrypt.doCheckPassword()` method implementation (https://github.com/bcgit/bc-java/blob/r1rv67/core/src/main/java/org/bouncycastle/crypto/generators/OpenBSDBCrypt.java#L259-L343) into their own utility class and supplement it with the required methods and variables as required
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2021:2755
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.3/
- externalhttps://access.redhat.com/articles/5975301
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1912881
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1923133
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1927028
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1929479
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1937364
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1937440
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1944888
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1948001
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1962879
- externalhttps://issues.redhat.com/browse/JBEAP-22122
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_2755.json