Red Hat Security Advisory: Red Hat support for Spring Boot 2.5.10 update
🔗 CVE IDs covered (9)
📋 Description
CVE-2021-3597 — undertow: HTTP2SourceChannel fails to write final frame under some circumstances may lead to DoS CVE-2021-3629 — undertow: potential security issue in flow control over HTTP/2 may lead to DOS CVE-2021-3642 — wildfly-elytron: possible timing attack in ScramServer CVE-2021-3859 — undertow: client side invocation timeout raised when calling over HTTP2 CVE-2021-20289 — resteasy: Error message exposes endpoint class information CVE-2021-30640 — tomcat: JNDI realm authentication weakness CVE-2021-33037 — tomcat: HTTP request smuggling when used with a reverse proxy CVE-2021-41079 — tomcat: Infinite loop while reading an unexpected TLS packet when using OpenSSL JSSE engine CVE-2021-42340 — tomcat: OutOfMemoryError caused by HTTP upgrade connection leak could lead to DoS
🎯 Affected products1
- Red Hat Support for Spring Boot 2.5.10
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link for the update. You must be logged in to download the update.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2022:1179
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=catRhoar.spring.boot&version=2.5.10
- externalhttps://access.redhat.com/documentation/en-us/red_hat_support_for_spring_boot/2.5/html/release_notes_for_spring_boot_2.5/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1935927
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1970930
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1977362
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1981407
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1981533
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1981544
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2004820
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2010378
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2014356
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_1179.json