Red Hat Security Advisory: Red Hat Fuse 7.12 release and security update
🔗 CVE IDs covered (27)
📋 Description
CVE-2012-5783 — jakarta-commons-httpclient: missing connection hostname check against X.509 certificate name CVE-2020-13956 — apache-httpclient: incorrect handling of malformed authority component in request URIs CVE-2022-4492 — undertow: Server identity in https connection is not checked by the undertow client CVE-2022-24785 — Moment.js: Path traversal in moment.locale CVE-2022-31692 — spring-security: Authorization rules can be bypassed via forward or include dispatcher types in Spring Security CVE-2022-36437 — hazelcast: Hazelcast connection caching CVE-2022-38398 — batik: Server-Side Request Forgery CVE-2022-38648 — batik: Server-Side Request Forgery CVE-2022-40146 — batik: Server-Side Request Forgery (SSRF) vulnerability CVE-2022-41704 — batik: Apache XML Graphics Batik vulnerable to code execution via SVG CVE-2022-41854 — dev-java/snakeyaml: DoS via stack overflow CVE-2022-41881 — codec-haproxy: HAProxyMessageDecoder Stack Exhaustion DoS CVE-2022-41940 — engine.io: Specially crafted HTTP request can trigger an uncaught exception CVE-2022-41946 — postgresql-jdbc: Information leak of prepared statement data due to insecure temporary file permissions CVE-2022-41966 — xstream: Denial of Service by injecting recursive collections or maps based on element's hash values raising a stack overflow CVE-2022-42890 — batik: Untrusted code execution in Apache XML Graphics Batik CVE-2022-42920 — Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing CVE-2022-45143 — tomcat: JsonErrorReportValve injection CVE-2022-46363 — CXF: directory listing / code exfiltration CVE-2022-46364 — CXF: SSRF Vulnerability CVE-2023-1108 — Undertow: Infinite loop in SslConduit during close CVE-2023-1370 — json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) CVE-2023-20860 — springframework: Security Bypass With Un-Prefixed Double Wildcard Pattern CVE-2023-20861 — springframework: Spring Expression DoS Vulnerability CVE-2023-20883 — spring-boot: Spring Boot Welcome Page DoS Vulnerability CVE-2023-22602 — shiro: Authentication bypass through a specially crafted HTTP request CVE-2023-33201 — bouncycastle: potential blind LDAP injection attack using a self-signed certificate
🎯 Affected products1
- Red Hat Fuse 7.12
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Sanitize the user-provided locale name before passing it to Moment.js.
🔗 References (34)
- selfhttps://access.redhat.com/errata/RHSA-2023:3954
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.fuse&version=7.12.0
- externalhttps://access.redhat.com/documentation/en-us/red_hat_fuse/7.12/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=873317
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1886587
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2072009
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2142707
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2144970
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2151988
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2153260
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2153379
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2153399
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2155291
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2155292
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2155295
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2155681
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2155682
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2158695
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2162053
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2162206
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2170431
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2174246
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2180528
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2180530
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182182
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182183
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182198
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2188542
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2209342
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2215465
- externalhttps://issues.redhat.com/browse/ENTESB-20598
- externalhttps://issues.redhat.com/browse/ENTESB-21418
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_3954.json