RHSA-2021:3425HighCVSS 7.5

Red Hat Security Advisory: Red Hat support for Spring Boot 2.3.10 security update

Published
September 9, 2021
Last Modified
August 4, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2020-27782 — undertow: special character in query results in server errors CVE-2021-3690 — undertow: buffer leak on incoming websocket PONG message may lead to DoS CVE-2021-24122 — tomcat: Information disclosure when using NTFS file system CVE-2021-25122 — tomcat: Request mix-up with h2c CVE-2021-25329 — tomcat: Incomplete fix for CVE-2020-9484 (RCE via session persistence)

🎯 Affected products1

  • Red Hat support for Spring Boot 2.3.10

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link for the update. You must be logged in to download the update. Workaround: The issue can be mitigated by using HTTP/1.1 instead of AJP to proxy to the back-end. Workaround: Users may configure the PersistenceManager with an appropriate value for sessionAttributeValueClassNameFilter to ensure that only application provided attributes are serialized and deserialized. For more details about the configuration, refer to the Apache Tomcat 9 Configuration Reference https://tomcat.apache.org/tomcat-9.0-doc/config/manager.html.

🔗 References (10)