RHSA-2022:1360LowCVSS 8.1

Red Hat Security Advisory: Red Hat Fuse 7.10.2 release and security update

Published
April 13, 2022
Last Modified
August 4, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2022-22965 — spring-framework: RCE via Data Binding on JDK 9+

🎯 Affected products1

  • Red Hat Fuse 7.10.2

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Installation instructions are available from the Fuse 7.10 product documentation page: https://access.redhat.com/documentation/en-us/red_hat_fuse/7.10/ Workaround: For those who are not able to upgrade affected Spring classes to the fixed versions, there is a workaround customers can implement for their applications, via setting disallowed fields on the data binder, and denying various iterations of the string "class.*" For full implementation details, see Spring's early announcement post in the "suggested workarounds" section: https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement#suggested-workarounds

🔗 References (6)