RHSA-2021:4100MediumCVSS 5.4
Red Hat Security Advisory: Red Hat Integration - Service Registry release and security update [2.0.2.GA]
🔗 CVE IDs covered (3)
📋 Description
CVE-2020-13956 — apache-httpclient: incorrect handling of malformed authority component in request URIs CVE-2021-20289 — resteasy: Error message exposes endpoint class information CVE-2021-20293 — RESTEasy: PathParam in RESTEasy can lead to a reflected XSS attack
🎯 Affected products1
- RHINT Service Registry 2.0.2 GA
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2021:4100
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1886587
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1935927
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1942819
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_4100.json