Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Red Hat Data Grid 8.2 Critical: RHSA-2021:2139-01 Authentication Bypass

red hat
Calendar Grey May 26, 2021
Dist Redhat Esm H88
Oracle announces an essential security patch for Database 19c, mitigating several issues within the application.
A security update for Red Hat Data Grid is now available

Solution

Refer to the Data Grid 8.2 Upgrade Guide for instructions on upgrading to this version.

The References section of this erratum contains a download link (you must log in to download the update).

Summary

Red Hat Data Grid is a distributed, in-memory data store.
This release of Red Hat Data Grid 8.2.0 serves as a replacement for Red Hat Data Grid 8.1.1, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.
Security Fix(es):
* Infinispan: Authentication bypass on REST endpoints when using DIGEST authentication mechanism (CVE-2021-31917)
* XStream: Unsafe deserizaliation of javax.sql.rowset.BaseRowSet (CVE-2021-21344)
* XStream: Unsafe deserizaliation of com.sun.corba.se.impl.activation.ServerTableEntry (CVE-2021-21345)
* XStream: Unsafe deserizaliation of sun.swing.SwingLazyValue (CVE-2021-21346)
* XStream: Unsafe deserizaliation of com.sun.tools.javac.processing.JavacProcessingEnvironment NameProcessIterator (CVE-2021-21347)
* XStream: Unsafe deserizaliation of com.sun.org.apache.bcel.internal.util.ClassLoader (CVE-2021-21350)
* Infinispan: Actions with effects should not be permitted via GET requests using REST API (CVE-2020-10771)
* XStream: Server-Side Forgery Request vulnerability can be activated when unmarshalling (CVE-2020-26258)
* XStream: arbitrary file deletion on the local host when unmarshalling (CVE-2020-26259)
* netty: Information disclosure via the local system temporary directory (CVE-2021-21290)
* netty: possible request smuggling in HTTP/2 due missing validation (CVE-2021-21295)
* XStream: allow a remote attacker to cause DoS only by manipulating the processed input stream (CVE-2021-21341)
* XStream: SSRF via crafted input stream (CVE-2021-21342)
* XStream: arbitrary file deletion on the local host via crafted input stream (CVE-2021-21343)
* XStream: ReDoS vulnerability (CVE-2021-21348)
* XStream: SSRF can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host (CVE-2021-21349)
* XStream: allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream (CVE-2021-21351)
* netty: Request smuggling via content-length header (CVE-2021-21409)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2020-10771 https://access.redhat.com/security/cve/CVE-2020-26258 https://access.redhat.com/security/cve/CVE-2020-26259 https://access.redhat.com/security/cve/CVE-2021-21290 https://access.redhat.com/security/cve/CVE-2021-21295 https://access.redhat.com/security/cve/CVE-2021-21341 https://access.redhat.com/security/cve/CVE-2021-21342 https://access.redhat.com/security/cve/CVE-2021-21343 https://access.redhat.com/security/cve/CVE-2021-21344 https://access.redhat.com/security/cve/CVE-2021-21345 https://access.redhat.com/security/cve/CVE-2021-21346 https://access.redhat.com/security/cve/CVE-2021-21347 https://access.redhat.com/security/cve/CVE-2021-21348 https://access.redhat.com/security/cve/CVE-2021-21349 https://access.redhat.com/security/cve/CVE-2021-21350 https://access.redhat.com/security/cve/CVE-2021-21351 https://access.redhat.com/security/cve/CVE-2021-21409 https://access.redhat.com/security/cve/CVE-2021-31917 https://access.redhat.com/security/updates/classification#critical https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=data.grid&version=8.2 https://docs.redhat.com/en/documentation/red_hat_data_grid/8.2/html/upgrading_data_grid/index

Package List


Severity
critical
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2021:2139-01
Product: Red Hat JBoss Data Grid
Issue date: 2021-05-26

Topic

A security update for Red Hat Data Grid is now available.Red Hat Product Security has rated this update as having a security impactof Critical. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Bugs Fixed

1846293 - CVE-2020-10771 Infinispan: Actions with effects should not be permitted via GET requests using REST API

1908832 - CVE-2020-26258 XStream: Server-Side Forgery Request vulnerability can be activated when unmarshalling

1908837 - CVE-2020-26259 XStream: arbitrary file deletion on the local host when unmarshalling

1927028 - CVE-2021-21290 netty: Information disclosure via the local system temporary directory

1937364 - CVE-2021-21295 netty: possible request smuggling in HTTP/2 due missing validation

1942539 - CVE-2021-21341 XStream: allow a remote attacker to cause DoS only by manipulating the processed input stream

1942545 - CVE-2021-21342 XStream: SSRF via crafted input stream

1942550 - CVE-2021-21343 XStream: arbitrary file deletion on the local host via crafted input stream

1942554 - CVE-2021-21344 XStream: Unsafe deserizaliation of javax.sql.rowset.BaseRowSet

1942558 - CVE-2021-21345 XStream: Unsafe deserizaliation of com.sun.corba.se.impl.activation.ServerTableEntry

1942578 - CVE-2021-21346 XStream: Unsafe deserizaliation of sun.swing.SwingLazyValue

1942629 - CVE-2021-21347 XStream: Unsafe deserizaliation of com.sun.tools.javac.processing.JavacProcessingEnvironment NameProcessIterator

1942633 - CVE-2021-21348 XStream: ReDoS vulnerability

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here