RHSA-2023:3954CriticalCVSS 9.8

Red Hat Security Advisory: Red Hat Fuse 7.12 release and security update

Published
June 29, 2023
Last Modified
August 18, 2026

🔗 CVE IDs covered (27)

📋 Description

CVE-2012-5783 — jakarta-commons-httpclient: missing connection hostname check against X.509 certificate name CVE-2020-13956 — apache-httpclient: incorrect handling of malformed authority component in request URIs CVE-2022-4492 — undertow: Server identity in https connection is not checked by the undertow client CVE-2022-24785 — Moment.js: Path traversal in moment.locale CVE-2022-31692 — spring-security: Authorization rules can be bypassed via forward or include dispatcher types in Spring Security CVE-2022-36437 — hazelcast: Hazelcast connection caching CVE-2022-38398 — batik: Server-Side Request Forgery CVE-2022-38648 — batik: Server-Side Request Forgery CVE-2022-40146 — batik: Server-Side Request Forgery (SSRF) vulnerability CVE-2022-41704 — batik: Apache XML Graphics Batik vulnerable to code execution via SVG CVE-2022-41854 — dev-java/snakeyaml: DoS via stack overflow CVE-2022-41881 — codec-haproxy: HAProxyMessageDecoder Stack Exhaustion DoS CVE-2022-41940 — engine.io: Specially crafted HTTP request can trigger an uncaught exception CVE-2022-41946 — postgresql-jdbc: Information leak of prepared statement data due to insecure temporary file permissions CVE-2022-41966 — xstream: Denial of Service by injecting recursive collections or maps based on element's hash values raising a stack overflow CVE-2022-42890 — batik: Untrusted code execution in Apache XML Graphics Batik CVE-2022-42920 — Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing CVE-2022-45143 — tomcat: JsonErrorReportValve injection CVE-2022-46363 — CXF: directory listing / code exfiltration CVE-2022-46364 — CXF: SSRF Vulnerability CVE-2023-1108 — Undertow: Infinite loop in SslConduit during close CVE-2023-1370 — json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) CVE-2023-20860 — springframework: Security Bypass With Un-Prefixed Double Wildcard Pattern CVE-2023-20861 — springframework: Spring Expression DoS Vulnerability CVE-2023-20883 — spring-boot: Spring Boot Welcome Page DoS Vulnerability CVE-2023-22602 — shiro: Authentication bypass through a specially crafted HTTP request CVE-2023-33201 — bouncycastle: potential blind LDAP injection attack using a self-signed certificate

🎯 Affected products1

  • Red Hat Fuse 7.12

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Sanitize the user-provided locale name before passing it to Moment.js.

🔗 References (34)