RHSA-2022:1179HighCVSS 7.5

Red Hat Security Advisory: Red Hat support for Spring Boot 2.5.10 update

Published
April 12, 2022
Last Modified
August 4, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2021-3597 — undertow: HTTP2SourceChannel fails to write final frame under some circumstances may lead to DoS CVE-2021-3629 — undertow: potential security issue in flow control over HTTP/2 may lead to DOS CVE-2021-3642 — wildfly-elytron: possible timing attack in ScramServer CVE-2021-3859 — undertow: client side invocation timeout raised when calling over HTTP2 CVE-2021-20289 — resteasy: Error message exposes endpoint class information CVE-2021-30640 — tomcat: JNDI realm authentication weakness CVE-2021-33037 — tomcat: HTTP request smuggling when used with a reverse proxy CVE-2021-41079 — tomcat: Infinite loop while reading an unexpected TLS packet when using OpenSSL JSSE engine CVE-2021-42340 — tomcat: OutOfMemoryError caused by HTTP upgrade connection leak could lead to DoS

🎯 Affected products1

  • Red Hat Support for Spring Boot 2.5.10

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link for the update. You must be logged in to download the update.

🔗 References (14)