RHSA-2023:1334CriticalCVSS 9.8

Red Hat Security Advisory: Red Hat Process Automation Manager 7.13.2 security update

Published
March 20, 2023
Last Modified
August 4, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2017-12629 — Solr: Code execution via entity expansion CVE-2018-1000134 — unboundid-ldapsdk: Incorrect Access Control vulnerability in process function in SimpleBindRequest class CVE-2019-19919 — nodejs-handlebars: prototype pollution leading to remote code execution via crafted payloads CVE-2019-20920 — nodejs-handlebars: lookup helper fails to properly validate templates allowing for arbitrary JavaScript execution CVE-2019-20922 — nodejs-handlebars: an endless loop while processing specially-crafted templates leads to DoS CVE-2021-23369 — nodejs-handlebars: Remote code execution when compiling untrusted compile templates with strict:true option CVE-2021-23383 — nodejs-handlebars: Remote code execution when compiling untrusted compile templates with compat:true option CVE-2021-26291 — maven: Block repositories using http by default

🎯 Affected products1

  • RHPAM 7.13.1 async

✅ Remediation

For on-premise installations, before applying the update, back up your existing installation including all applications, configuration files, databases and database settings, and so on. Red Hat recommends that you halt the server by stopping the JBoss Application Server process before installing this update. After installing the update, restart the server by starting the JBoss Application Server process. The References section of this erratum contains a download link. You must log in to download the update. Workaround: Until fixes are available, all Solr users are advised to restart their Solr instances with the system parameter `-Ddisable.configEdit=true`. This will disallow any changes to be made to configurations via the Config API. This is a key factor in this vulnerability, since it allows GET requests to add the RunExecutableListener to the config. This is sufficient to protect from this type of attack, but means you cannot use the edit capabilities of the Config API until further fixes are in place. Workaround: To avoid possible man-in-the-middle related attacks with this flaw, ensure any linked repositories in maven POMs use https and not http.

🔗 References (11)