Linux Security
    Linux Security
    Linux Security

    RedHat: RHSA-2020-2252:01 Important: Red Hat support for Spring Boot 2.2.6

    Date
    255
    Posted By
    An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA256
    
    =====================================================================
                       Red Hat Security Advisory
    
    Synopsis:          Important: Red Hat support for Spring Boot 2.2.6 security and bug fix update
    Advisory ID:       RHSA-2020:2252-01
    Product:           Red Hat OpenShift Application Runtimes
    Advisory URL:      https://access.redhat.com/errata/RHSA-2020:2252
    Issue date:        2020-06-01
    CVE Names:         CVE-2020-1697 CVE-2020-1698 CVE-2020-1718 
                       CVE-2020-1724 CVE-2020-1727 CVE-2020-1744 
    =====================================================================
    
    1. Summary:
    
    An update is now available for Red Hat OpenShift Application Runtimes.
    
    Red Hat Product Security has rated this update as having a security impact
    of Important. A Common Vulnerability Scoring System (CVSS) base score,
    which gives a detailed severity rating, is available for each vulnerability
    from the CVE link(s) in the References section.
    
    2. Description:
    
    Red Hat support for Spring Boot provides an application platform that
    reduces the complexity of developing and operating applications (monoliths
    and microservices) for OpenShift as a containerized platform.
    
    This release of Red Hat support for Spring Boot 2.2.6 serves as a
    replacement for Red Hat support for Spring Boot 2.1.13, and includes
    security and bug fixes and enhancements. For further information, refer to
    the release notes linked to in the References section.
    
    Security Fix(es):
    
    * keycloak: security issue on reset credential flow (CVE-2020-1718)
    
    * keycloak: stored XSS in client settings via application links
    (CVE-2020-1697)
    
    * keycloak: missing input validation in IDP authorization URLs
    (CVE-2020-1727)
    
    * keycloak: Password leak by logged exception in HttpMethod class
    (CVE-2020-1698)
    
    * keycloak: problem with privacy after user logout (CVE-2020-1724)
    
    * keycloak: failedLogin Event not sent to BruteForceProtector when using
    Post Login Flow with Conditional-OTP (CVE-2020-1744)
    
    For more details about the security issue(s), including the impact, a CVSS
    score, acknowledgments, and other related information, refer to the CVE
    page(s) listed in the References section.
    
    3. Solution:
    
    Before applying the update, back up your existing installation, including
    all applications, configuration files, databases and database settings, and
    so on.
    
    The References section of this erratum contains a download link (you must
    log in to download the update).
    
    4. Bugs fixed (https://bugzilla.redhat.com/):
    
    1790292 - CVE-2020-1698 keycloak: Password leak by logged exception in HttpMethod class
    1791538 - CVE-2020-1697 keycloak: stored XSS in client settings via application links
    1796756 - CVE-2020-1718 keycloak: security issue on reset credential flow
    1800527 - CVE-2020-1724 keycloak: problem with privacy after user logout
    1800573 - CVE-2020-1727 keycloak: missing input validation in IDP authorization URLs
    1805792 - CVE-2020-1744 keycloak: failedLogin Event not sent to BruteForceProtector when using Post Login Flow with Conditional-OTP
    
    5. References:
    
    https://access.redhat.com/security/cve/CVE-2020-1697
    https://access.redhat.com/security/cve/CVE-2020-1698
    https://access.redhat.com/security/cve/CVE-2020-1718
    https://access.redhat.com/security/cve/CVE-2020-1724
    https://access.redhat.com/security/cve/CVE-2020-1727
    https://access.redhat.com/security/cve/CVE-2020-1744
    https://access.redhat.com/security/updates/classification/#important
    https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=catRhoar.spring.boot&version=2.2.6
    https://access.redhat.com/documentation/en-us/red_hat_support_for_spring_boot/
    
    6. Contact:
    
    The Red Hat security contact is . More contact
    details at https://access.redhat.com/security/team/contact/
    
    Copyright 2020 Red Hat, Inc.
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1
    
    iQIVAwUBXtUfrtzjgjWX9erEAQjILA//SJVcOXK4mXfZ5+GmUGu2q7bxTBwsWHzJ
    CedomHVugs0L6lePsEP1Ft89x5U32tnnJR//a2t/tKD+PYyKz7o9ZUfeACPQj+aP
    Oftq4grNMVMDsNy+4mJawPvHFGZ2kNlmMLF6xoOW1ebjyFim5XhIIccBzd3dWzOA
    5dp77tWEX7ZUo5FL29SK4dlk5h9jV9WHHlPw2O+xrvQ+KPfPLTPNqHRW/vCW/AEl
    0F/QvaZOq4eqhQgpXCCN7eC3bMBCbHebd9g/fwmdjuAlF3peBEz9+D7MXTzUmuzb
    T1I7bGWgBNoXQrDVJfe1sFW364YUrirtC5HcJ+cSuuupM/ztcizc0ds/S4dZIrGU
    TeuDq1uwHKE1tl3mjzaxBSpUGJjuxQt0sw2Pq5+yP7rNrgWH3HH9sJ9hmhuO4xU7
    Zfn0IUpE3QB8TjlILF6fiaUgCJnXaTSzDLbmGt2pDcaJqGZN9cKiwolSM33DoDzb
    EgEB/0rPRmd7RqUfdHTlLlV1n6A1Q4wJjqpn08j9np8bpR3NkPExhC8itG9hFCBk
    9JCtN0ZgZsaFMjlRgk/aC25aJWBRa+DPsq61sj39fwCoPxfBd8LOreiAedZkyKeh
    YHVmwJWN7C2/Yv7me9/5Pq8HpHJ4MaUawvZ7ndg8FOuGoI1V7rXuRf/2DI+zz8hR
    luq8oLenEA4=
    =RTbh
    -----END PGP SIGNATURE-----
    
    --
    RHSA-announce mailing list
    This email address is being protected from spambots. You need JavaScript enabled to view it.
    https://www.redhat.com/mailman/listinfo/rhsa-announce
    

    Advisories

    LinuxSecurity Poll

    How are you contributing to Open Source?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 4 answer(s).
    /main-polls/37-how-are-you-contributing-to-open-source?task=poll.vote&format=json
    37
    radio
    [{"id":"127","title":"I'm involved with the development of an open-source project(s).","votes":"1","type":"x","order":"1","pct":100,"resources":[]},{"id":"128","title":"I've reported vulnerabilities I've discovered in open-source code.","votes":"0","type":"x","order":"2","pct":0,"resources":[]},{"id":"129","title":"I've provided developers with feedback on their projects.","votes":"0","type":"x","order":"3","pct":0,"resources":[]},{"id":"130","title":"I've helped another community member get started contributing to Open Source.","votes":"0","type":"x","order":"4","pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350


    VIEW MORE POLLS

    bottom 200

    Please enable / Bitte aktiviere JavaScript!
    Veuillez activer / Por favor activa el Javascript![ ? ]

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.