Red Hat Security Advisory: Red Hat Process Automation Manager 7.13.4 security update
🔗 CVE IDs covered (18)
📋 Description
CVE-2021-30129 — mina-sshd-core: Memory leak denial of service in Apache Mina SSHD Server CVE-2022-3143 — wildfly-elytron: possible timing attacks via use of unsafe comparator CVE-2022-3171 — protobuf-java: timeout in parser leads to DoS CVE-2022-3509 — protobuf-java: Textformat parsing issue leads to DoS CVE-2022-3510 — protobuf-java: Message-Type Extensions parsing issue leads to DoS CVE-2022-4492 — undertow: Server identity in https connection is not checked by the undertow client CVE-2022-25857 — snakeyaml: Denial of Service due to missing nested depth limitation for collections CVE-2022-37599 — loader-utils: regular expression denial of service in interpolateName.js CVE-2022-38900 — decode-uri-component: improper input validation resulting in DoS CVE-2022-40152 — woodstox-core: woodstox to serialise XML data was vulnerable to Denial of Service attacks CVE-2022-41854 — dev-java/snakeyaml: DoS via stack overflow CVE-2022-42920 — Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing CVE-2022-45047 — mina-sshd: Java unsafe deserialization vulnerability CVE-2023-0482 — RESTEasy: creation of insecure temp files CVE-2023-20860 — springframework: Security Bypass With Un-Prefixed Double Wildcard Pattern CVE-2023-20861 — springframework: Spring Expression DoS Vulnerability CVE-2023-20883 — spring-boot: Spring Boot Welcome Page DoS Vulnerability CVE-2023-24998 — FileUpload: FileUpload DoS with excessive parts
🎯 Affected products1
- RHPAM 7.13.4 async
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: From the maintainer: For Apache MINA SSHD <= 2.9.1, do not use org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider to generate and later load your server's host key. Use separately generated host key files, for instance in OpenSSH format, and load them via a org.apache.sshd.common.keyprovider.FileKeyPairProvider instead. Or use a custom implementation instead of SimpleGeneratorHostKeyProvider that uses the OpenSSH format for storing and loading the host key (via classes OpenSSHKeyPairResourceWriter and OpenSSHKeyPairResourceParser).
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2023:4983
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1981527
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2126789
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134291
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134872
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2137645
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2142707
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2145194
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2166004
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2170644
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2180528
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2209342
- externalhttps://issues.redhat.com/browse/RHPAM-4639
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_4983.json