Red Hat Integration Camel for Spring Boot 3.20.2 release and security update is now available. Red Hat Product Security has rated this update as having an impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Integration Camel for Spring Boot 3.20.2 release and security update Advisory ID: RHSA-2023:5148-01 Product: Red Hat Integration Advisory URL: https://access.redhat.com/errata/RHSA-2023:5148 Issue date: 2023-09-13 CVE Names: CVE-2023-20873 CVE-2023-34455 ===================================================================== 1. Summary: Red Hat Integration Camel for Spring Boot 3.20.2 release and security update is now available. Red Hat Product Security has rated this update as having an impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat Integration Camel for Spring Boot 3.20.2 is now available. The purpose of this text-only errata is to inform you about the security issues fixed. Security Fix(es): * spring-boot: Security Bypass With Wildcard Pattern Matching on Cloud Foundry (CVE-2023-20873) * snappy-java: Unchecked chunk length leads to DoS (CVE-2023-34455) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2215445 - CVE-2023-34455 snappy-java: Uncheckedchunk length leads to DoS 2231491 - CVE-2023-20873 spring-boot: Security Bypass With Wildcard Pattern Matching on Cloud Foundry 5. References: https://access.redhat.com/security/cve/CVE-2023-20873 https://access.redhat.com/security/cve/CVE-2023-34455 https://access.redhat.com/security/updates/classification#important https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2023-Q3 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJlAikfAAoJENzjgjWX9erE99YP/i5C3Va6yTCslqiNPOj8cOhy OC1tdof6RVbOxWysA+u4mOSHLQGCO3WJC5ujoTjBLwnyiW0jsQNZywc6MxvFZVi2 cpd6ZUc6GcOEgXppKmB6kOKckTjK9x2J1Pp99sBaUu1JjjsPHKtiIU7UpxDfbj0x l8LKCbFnjvzEc9iLiORTMrR0x+Di72v1g+pDppkF6cLPISQjmaoy2fFPGOk+QNir OyR6ftdOUwouMpwoeBYA9LNUtj4L4LIwNo7/XUAM37KpgsDjrIugI03BW55WZetu U4fJ2iiCnNRNi7RbQgBoBsAk84wDvZ3CUlsObuJzUnbZO8AHwtTKNLDCXBDXV39N qDhN6Qsf+ODX4XRy92Q7e734bLyKBCdo0JoOq6b3bVP0AxDNnM+vf+1WAD2dnU0F mVEswKVJ3pex7jgw7tsVeGG7QtDLUD3JC1Sg9/wxXZfjmYxr//5e+BPqb0DY3CQ1 VK+Ctx/ovR0sHqmTUFMTgupaVqn/6h9nl16QUpDBY3BiP6QOcgBIAMdZoWDzkdOv Tg/GiEeofpISrxAVtxJXMAcnJA7XmyfaEa6Ks4kqFM5Jd5q+z8tKsePB+SYprL0K 9DLXWQpud7FydFnjzS2HtE85md/LCxBiuGhX8LTqAd0S/n/snKTU3vf7rbDs0uYq +au4fOPXeWAsGf5whih/ =jfNi -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Red Hat Integration Camel for Spring Boot 3.18.3.2 release and security update is now available. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having an impact of. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Integration Camel for Spring Boot 3.18.3.2 release and security update Advisory ID: RHSA-2023:5147-01 Product: Red Hat Integration Advisory URL: https://access.redhat.com/errata/RHSA-2023:5147 Issue date: 2023-09-13 CVE Names: CVE-2021-46877 CVE-2023-20873 CVE-2023-33201 CVE-2023-34455 ===================================================================== 1. Summary: Red Hat Integration Camel for Spring Boot 3.18.3.2 release and security update is now available. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having an impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: A security update for Camel for Spring Boot 3.18.3.2 is now available. The purpose of this text-only errata is to inform you about the security issues fixed in this release. * spring-boot: Security Bypass With Wildcard Pattern Matching on Cloud Foundry (CVE-2023-20873) * jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode (CVE-2021-46877) * bouncycastle: potential blind LDAP injection attack using a self-signed certificate (CVE-2023-33201) * snappy-java: Unchecked chunk length leads to DoS (CVE-2023-34455) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other relatedinformation, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2185707 - CVE-2021-46877 jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode 2215445 - CVE-2023-34455 snappy-java: Unchecked chunk length leads to DoS 2215465 - CVE-2023-33201 bouncycastle: potential blind LDAP injection attack using a self-signed certificate 2231491 - CVE-2023-20873 spring-boot: Security Bypass With Wildcard Pattern Matching on Cloud Foundry 5. References: https://access.redhat.com/security/cve/CVE-2021-46877 https://access.redhat.com/security/cve/CVE-2023-20873 https://access.redhat.com/security/cve/CVE-2023-33201 https://access.redhat.com/security/cve/CVE-2023-34455 https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2023-Q3 https://access.redhat.com/security/updates/classification#important 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJlAikdAAoJENzjgjWX9erEY04P/iSm4Sumuu8ke2lI2WqpIdvO GDOr9DgtoWEhuJTTGaIYTO5qO2DBfuP8VwqL4Px12zmcQrq1j0txFOEVSWGGSgT1 KddBmIG9ERwkbKH+t5styPYwWtu5T5jQImVLjHOVNWIsQ0PL2dgZuOaGjLMGY4DL jvTViXGGLnjomR9jf9EIj59KRGklKp9hFwE4SGarH3RSQchu+94uPeYXVK7ifbx+ SWWHthI6+XsO3MKaXiX60OpgPODS7gtvVnlk/9ZqeYOa4TLLBjxNGskw2H8m+fGD wVThEvVFOL0Co5tPlXH785wguzcDI/77wp9FKNKdudfkNyE4rt0uIns8HZ5F71yv YzhD/Z4bi/oHlwCN9WuDYCMEuI2YDf5oB1m4hL10nr9j48izi316ru4HvU7pSd/3 JtNzIdWyMtKFMrNas8P6GrlJueXhpv1QFc9S4t42bGoZvdfYfvPeOttsjbnoN93H fN+O1guY+9ngVc6/UP2z1S2p4YZNUVganHLR/P9rmWMhamX7qAMpqJmBiu8xtb5u pssgpr0PPrYI9LZsVofeXK2H/l7OvhaoL8WdA3YFZe2uNknDPrINNKsHBaqI/d5W YAI5cnNzwQSUGyK+oeDl4O04Frj3ntrlhfGRA971kfTkweZnjOB8ComPOpHKiCsf FVJiEkqhQ7jUG3NbQ5TP =HZ7/ -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Red Hat Integration Camel for Spring Boot 3.20.1 Patch 1 release and security update is now available. Red Hat Product Security has rated this update as having an impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Integration Camel for Spring Boot 3.20.1 Patch 1 release security update Advisory ID: RHSA-2023:3740-01 Product: Red Hat Integration Advisory URL: https://access.redhat.com/errata/RHSA-2023:3740 Issue date: 2023-06-21 CVE Names: CVE-2023-20883 CVE-2023-24815 ==================================================================== 1. Summary: Red Hat Integration Camel for Spring Boot 3.20.1 Patch 1 release and security update is now available. Red Hat Product Security has rated this update as having an impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: This release of Camel for Spring Boot 3.20.1.P1 serves as a replacement for Camel for Spring Boot 3.20.1 and includes bug fixes and enhancements, which are documented in the Release Notes linked in the References. The purpose of this text-only errata is to inform you about the security issues fixed. Security Fix(es): * vertx-web: StaticHandler disclosure of classpath resources on Windows when mounted on a wildcard route (CVE-2023-24815) * spring-boot: Spring Boot Welcome Page DoS Vulnerability (CVE-2023-20883) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have beenapplied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2209342 - CVE-2023-20883 spring-boot: Spring Boot Welcome Page DoS Vulnerability 2209400 - CVE-2023-24815 vertx-web: StaticHandler disclosure of classpath resources on Windows when mounted on a wildcard route 5. References: https://access.redhat.com/security/cve/CVE-2023-20883 https://access.redhat.com/security/cve/CVE-2023-24815 https://access.redhat.com/security/updates/classification#important https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2023-Q2 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZJNxFdzjgjWX9erEAQjgyg/8DIsEGsp2KcG+EMZiGqVlBaafePfT3gP6 tVOVD4jqsxQYLNa05/IZQtW5Do+0q1vF+ElMq073BgiTXzx6dvD2gppr+Z4DJfAt tvigw2uRofa+ycyL7LxtguxuwUEOrroEiCSqV5itQ/VKiPGoWbQ9WW7LJqPoL/l3 bOywYNbjQ9DIruTwaWt5YbdzYeCPiyh1lW+pG5wzci7m2DZoRu4mR+cV+XsY0XRS cGS5UtE60bXpid5CUFVKno26ArmY1twpb3hB8cX2xrjwa9xOpfteffdqp6bLM9Fv CfnjBSJLRiOIucR2d3jgWaMFsQlfpxRGfp/1fT9bI3RJ5RO2p0BHUS4ECAeCXCNW PhrmMfHKthHeQKSNpWPTKt+XgO1jE8qMATic5/hB3PL6w2KqFs8mSWePrhD3Vo1J SktXfBa3Sd1V3TbOz2otcifMCzg7ry95+sSR72Zpu/nQfP+keOsian98FdRlGzV5 Hh2l98+YgdtmNFp4rwrVCcOLluv/rzt7oG1UBYVM9ATV50fXqtU8KR7YRS3ooNj3 kaHBDTsUpqdl+iN25jpeDooLZkCKPcGsm7Pg6bUFjYkIHavxFwve9hVxXp9yiVL6 446ILywCJFF2/hsD7o0Pe4r6Gc9le6zh7C/6kqa+hb1k9aGtcwFnMaNK1H2Y3zni 4j/W1dDwivU=xseK -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Camel for Spring Boot 3.18.3 Patch 2 release and security update is now available. Red Hat Product Security has rated this update as having an impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Integration Camel for Spring Boot 3.18.3 Patch 2 release Advisory ID: RHSA-2023:3641-01 Product: Red Hat Integration Advisory URL: https://access.redhat.com/errata/RHSA-2023:3641 Issue date: 2023-06-15 CVE Names: CVE-2022-25857 CVE-2022-38749 CVE-2022-38750 CVE-2022-38751 CVE-2022-38752 CVE-2022-40152 CVE-2022-40156 CVE-2022-41854 CVE-2022-42003 CVE-2022-42004 CVE-2022-45047 CVE-2022-46363 CVE-2022-46364 CVE-2023-1370 CVE-2023-1436 CVE-2023-20883 ==================================================================== 1. Summary: Camel for Spring Boot 3.18.3 Patch 2 release and security update is now available. Red Hat Product Security has rated this update as having an impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: This release of Camel for Spring Boot 3.18.3.P2 serves as a replacement for Camel for Spring Boot 3.18.3.P1 and includes bug fixes and enhancements, which are documented in the Release Notes linked in the References. The purpose of this text-only errata is to inform you about the security issues fixed. * spring-boot: Spring Boot Welcome Page DoS Vulnerability (CVE-2023-20883) * woodstox-core: woodstox to serialise XML data was vulnerable to Denial of Service attacks (CVE-2022-40152) * xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks(CVE-2022-40156) * dev-java-snakeyaml: dev-java/snakeyaml: DoS via stack overflow (CVE-2022-41854) * snakeyaml: Denial of Service due to missing nested depth limitation for collections (CVE-2022-25857) * sshd-common: mina-sshd: Java unsafe deserialization vulnerability (CVE-2022-45047) * jettison: Uncontrolled Recursion in JSONArray (CVE-2023-1436) * json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) (CVE-2023-1370) * jackson-databind: use of deeply nested arrays (CVE-2022-42004) * jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS (CVE-2022-42003) * snakeyaml: Uncaught exception in org.yaml.snakeyaml.composer.Composer.composeSequenceNode (CVE-2022-38749) * snakeyaml: Uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObject (CVE-2022-38750) * snakeyaml: Uncaught exception in java.base/java.util.regex.Pattern.match (CVE-2022-38751) * snakeyaml: Uncaught exception in java.base/java.util.ArrayList.hashCode (CVE-2022-38752) * snakeyaml: Denial of Service due to missing nested depth limitation for collections (CVE-2022-25857) * CXF: Apache CXF: directory listing / code exfiltration (CVE-2022-46363) * CXF: Apache CXF: SSRF Vulnerability (CVE-2022-46364) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2126789 - CVE-2022-25857 snakeyaml: Denial of Service due to missing nested depth limitation for collections 2129706 - CVE-2022-38749 snakeyaml: Uncaught exception in org.yaml.snakeyaml.composer.Composer.composeSequenceNode 2129707 - CVE-2022-38750 snakeyaml: Uncaught exception inorg.yaml.snakeyaml.constructor.BaseConstructor.constructObject 2129709 - CVE-2022-38751 snakeyaml: Uncaught exception in java.base/java.util.regex.Pattern$Ques.match 2129710 - CVE-2022-38752 snakeyaml: Uncaught exception in java.base/java.util.ArrayList.hashCode 2134288 - CVE-2022-40156 xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks 2134291 - CVE-2022-40152 woodstox-core: woodstox to serialise XML data was vulnerable to Denial of Service attacks 2135244 - CVE-2022-42003 jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS 2135247 - CVE-2022-42004 jackson-databind: use of deeply nested arrays 2145194 - CVE-2022-45047 mina-sshd: Java unsafe deserialization vulnerability 2151988 - CVE-2022-41854 dev-java/snakeyaml: DoS via stack overflow 2155681 - CVE-2022-46363 Apache CXF: directory listing / code exfiltration 2155682 - CVE-2022-46364 Apache CXF: SSRF Vulnerability 2182788 - CVE-2023-1436 jettison: Uncontrolled Recursion in JSONArray 2188542 - CVE-2023-1370 json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) 2209342 - CVE-2023-20883 spring-boot: Spring Boot Welcome Page DoS Vulnerability 5.References: https://access.redhat.com/security/cve/CVE-2022-25857 https://access.redhat.com/security/cve/CVE-2022-38749 https://access.redhat.com/security/cve/CVE-2022-38750 https://access.redhat.com/security/cve/CVE-2022-38751 https://access.redhat.com/security/cve/CVE-2022-38752 https://access.redhat.com/security/cve/CVE-2022-40152 https://access.redhat.com/security/cve/CVE-2022-40156 https://access.redhat.com/security/cve/CVE-2022-41854 https://access.redhat.com/security/cve/CVE-2022-42003 https://access.redhat.com/security/cve/CVE-2022-42004 https://access.redhat.com/security/cve/CVE-2022-45047 https://access.redhat.com/security/cve/CVE-2022-46363 https://access.redhat.com/security/cve/CVE-2022-46364 https://access.redhat.com/security/cve/CVE-2023-1370 https://access.redhat.com/security/cve/CVE-2023-1436 https://access.redhat.com/security/cve/CVE-2023-20883 https://access.redhat.com/security/updates/classification#important https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2023-Q2 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZItdGNzjgjWX9erEAQhc7A/+PfKtOHtO40HR87HLkZdBROVscSVLLgYJ y0yTSOnpx2ccBCkpvEA6+7nzu8l3IZFrmAuSkzMJN84oWVyrzRi+BcrAfAB0J7Il ItShHVcEJvSzNDrDb9BZ37awga9w/rEkx6h8DwdItClBIlGyaTHhL7dF1XrWSbti 1Nes6J/FSTVjiW7PDbjb3IL9wB6NAkU+X0vJaOn9DWiInOiAlttaxdupy4GfwO7c 5tg4po/h2IxCcz7TEHri+Oiyucc014cedEeSizguKqYs16rspagFZGYcM460Qrg/ cYRPU6NwcYc/tfDubiWle3U7hYbzmY6+DffVS9ksTXz66W2jwWkn1SRJTnk4RsC8 hWnbxkYcPL24T3gCivZyrRgIX3VDi3RNRR7aYzNR+fWi790noi4Zz0smnO95w2XA vyfIRZLfCsgWnKPWo2E8tzanm3jfyorpBao6HvMeKcFhfPFV7Y8ERDNDoS7huU4H 67NWwTThGGNawChpLxCOkhaIB/tPMAU9EulswBZbRpRXWXaTG8+/OCGO4dZ3x+Wq RKybaXvqhIFFITP4gu5XraX/Y/ZbxRi9Qp0w7L0X3lvDE8GQqu2rZ2nSh9oRRKJE g7/7LGWtHMS8GfcvnBdlbl1a4NXKLkfLZjaZytAjoj9Yr2A8blAIe8fjRpan8Xmq s4LHK2NgW6M=jD7D -----END PGPSIGNATURE----- -- RHSA-announce mailing list
An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat support for Spring Boot 2.7.2.SP1 security update Advisory ID: RHSA-2023:0272-01 Product: Red Hat OpenShift Application Runtimes Advisory URL: https://access.redhat.com/errata/RHSA-2023:0272 Issue date: 2023-02-06 CVE Names: CVE-2022-23181 ==================================================================== 1. Summary: An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat support for Spring Boot provides an application platform that reduces the complexity of developing and operating applications (monoliths and microservices) for OpenShift as a containerized platform. This release of Red Hat support for Spring Boot 2.7.2.SP1 serves as a replacement for Red Hat support for Spring Boot 2.7.2, and includes security, bug fixes, and enhancements. For more information, see the release notes linked to in the References section. Security Fix(es): * tomcat: local privilege escalation vulnerability (CVE-2022-23181) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying the update, back up your existing installation,including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link for the update. You must be logged in to download the update. 4. Bugs fixed (https://bugzilla.redhat.com/): 2047417 - CVE-2022-23181 tomcat: local privilege escalation vulnerability 5. References: https://access.redhat.com/security/cve/CVE-2022-23181 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=catRhoar.spring.boot&version=2.7.2.SP1 https://access.redhat.com/documentation/en-us/red_hat_support_for_spring_boot/2.7/html/release_notes_for_spring_boot_2.7/index 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY+FwUdzjgjWX9erEAQjFqw//f+Uqe73F+me6wUuE/C1OCHSgXDqEZYZd N0jC65ebt2AT1aSettVnT+ZO+YZQ12PpZV/e23F32gR4EhmNFQtkqG4yBBp4oJ+0 5lKCl1DSylWTl1NeLDeI26WjnqpXF1LQHIEco+0qu//OZBXAnjJ3cAncx2NmRHC0 R7REST1ilC3gJ6ALuV5SgJAbGl6A8eG0F05smX2ZPBf6KDVIIvHpxFL0NlOIVHRD e1ZKfGVtKR43KDvqp5/DXCvRAKIUdNe/Hftl7FiZsJsxJ02GjiTH2EJ2797nYaJw DAEZ9alH5FZ9HDsUOWZO+3eHkc49QbWgHzI81FJAlVRzjxfyjHESGmk7l6OrFbmD cNjljrD11iEtyMCCofnkLfYiGCv+OFQxC4eAJ/Vqxy/oS4mIx4dExUU8Sf+Edx47 57zLfJa1MPXSvleWfOFwQbnTz3LZ60CIvdrdVqtWwWWqfT3cROn4bslP2Xu0JRul +bN6wi29jKV8av+eYf6xNRCc5ikcYeIppLNK18M3Z4n3+dOLbQwKLnK2O3UoMHBx ZdOU1dBRMAYsIV106v4UvjirsQ2PPTOOBWiuzZVHfg133wqMLHDorPUsoZSBktsM NUiyn+gEtEbSquBIfmD4tiMBPiFELw2FvaNs+AK/+d/L9oyXcXB4xATgvN65TnU/ U5ux9Itu+MI=VP/1 -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update is now available for Red Hat support for Spring Boot. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat support for Spring Boot 2.2.11 security update Advisory ID: RHSA-2020:5388-01 Product: Red Hat OpenShift Application Runtimes Advisory URL: https://access.redhat.com/errata/RHSA-2020:5388 Issue date: 2021-01-07 CVE Names: CVE-2020-11996 CVE-2020-25638 ==================================================================== 1. Summary: An update is now available for Red Hat support for Spring Boot. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. For more information, see the CVE links in the References section. 2. Description: Red Hat support for Spring Boot provides an application platform that reduces the complexity of developing and operating applications (monoliths and microservices) for OpenShift as a containerized platform. This release of Red Hat support for Spring Boot 2.2.11 serves as a replacement for Red Hat support for Spring Boot 2.2.10, and includes security and bug fixes and enhancements. For more information, see the release notes listed in the References section. Security Fix(es): * hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used (CVE-2020-25638) * tomcat: specially crafted sequence of HTTP/2 requests can lead to DoS (CVE-2020-11996) For more details about the security issues and their impact, the CVSS score, acknowledgements, and other relatedinformation, see the CVE pages listed in the References section. 3. Solution: Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link for the update. You must be logged in to download the update. 4. Bugs fixed (https://bugzilla.redhat.com/): 1851420 - CVE-2020-11996 tomcat: specially crafted sequence of HTTP/2 requests can lead to DoS 1881353 - CVE-2020-25638 hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used 5. References: https://access.redhat.com/security/cve/CVE-2020-11996 https://access.redhat.com/security/cve/CVE-2020-25638 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=catRhoar.spring.boot&version=2.2.11 https://access.redhat.com/documentation/en-us/red_hat_support_for_spring_boot/2.2/ 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBX/b1etzjgjWX9erEAQjZcQ/9G5Y11zAGobjakM8dwlbHwBuYCRHSpKRW JjwwtG9cWL/GYN8+x/AZwDwehODarYPaDW+3bmwgGhRFy9JZdWFQ7lOdT/9Co4wb mj/xpdOe7xZ9weqeaJZW/iw3TzH0V0puz6fklpZjMpZrglyxWYedBlsMp8x786Yf juHL9iG18XQP1w4CB5a+86tp06/xHBfPlnaxA8V9ULFHPKoIZzPCXDMXNVgO49yc bvn3xvYPmC3g0jb281mT9R2Kw0KC83azJyw8LlojfyKCcAq7JOeWRmNA0l3Nipdb iSRrkrBU52zAk4BmXAGwITJP4xOIdwlDyQvrqCVpqL76CLWVDXPRpA9Xj6+Nj1s0 uXvU+lww71SuUDMB9U7YniY6qr34oEOfBXB9stPNkpN/MpeO6woMPHNUZI8g5QT0 IIuOKUQRTUGz920J+yCF9RdXaWSJmTA8lxzbP7FHTYbNOnLTBOjrjBOd9Zp6bk/6 sXr2LxQPowPhi4Pa/Mzs6fkI2XYoIfJVNb62rPpT9HfpsvLJDa6PbOhj1vaodohR kICRSqV243C+v7DYzIcKRgYp+As5LfisOt3IOd1KPN71OFcdeJSaK4DcTEeWQYI2 JT6gWKsrcl82Hv6XxNQ0QGy+4iMAaTbUhygtNvF+E64fAAIii4e2ISnJDWSRpXx4 h87fw1ApUvM=dmJO -----END PGP SIGNATURE----- -- RHSA-announcemailing list
An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: Red Hat support for Spring Boot 2.2.10 security update Advisory ID: RHSA-2020:4213-01 Product: Red Hat OpenShift Application Runtimes Advisory URL: https://access.redhat.com/errata/RHSA-2020:4213 Issue date: 2020-10-08 CVE Names: CVE-2020-1728 ==================================================================== 1. Summary: An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat support for Spring Boot provides an application platform that reduces the complexity of developing and operating applications (monoliths and microservices) for OpenShift as a containerized platform. This release of Red Hat support for Spring Boot 2.2.10 serves as a replacement for Red Hat support for Spring Boot 2.2.6.SP2, and includes security and bug fixes and enhancements. For further information, refer to the release notes linked to in the References section. Security Fix(es): * keycloak: security headers missing on REST endpoints (CVE-2020-1728) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying the update, back up your existing installation,including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). 4. Bugs fixed (https://bugzilla.redhat.com/): 1800585 - CVE-2020-1728 keycloak: security headers missing on REST endpoints 5. References: https://access.redhat.com/security/cve/CVE-2020-1728 https://access.redhat.com/security/updates/classification/#low https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=catRhoar.spring.boot&version=2.2.10 https://access.redhat.com/documentation/en-us/red_hat_support_for_spring_boot/2.2/ 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBX37p/tzjgjWX9erEAQjzng//cQp9Pr5Mcu5e3wtBnCcTQy7rzB/T519O rfaGyWO8KGs71kLHf9btfEhoTtKRhgacg9k/SUZAH8BOFwrdeu1QApMGBfEtDcsZ 44J/W90b3jp2hL1oUPx/Xjv3cfZ6349NxAvSrzt1aL3Cmb0X8VDaF5PaXhXg9LEN it5WPWwWt5mk2JH6dTaVAN8gZrCSosR7hjQzyGGrIzT4hnWGKFaCcRE/NTeTBrB2 C8hglDoXw0LFNtHA8gQTh/BCRojXZ0tj2xGbysY+iPpyPFx9KaQ2AtRmCm9g3WUS K8pbu5G4+bOfeG9fFWjVLP1TcOiQ9mhlTlRtyMIRRizxtM4uIBjilYTE9CsOBZZe yVab5LUJiRpAh1qUVT6vXo/lrmXfgJXRPfnsj9TgJqeDbUNzasfNU5bJMadblc5p rjTy7FxvKPgdgzaBbz7aes1f1PiSTDbgCeKn8GBb3rVkMlGooYMaIdkAW0yO0h4Y +IdOtWoXkIemD8+7jhxP35WMOGEB1GjR45HGSQp+9QhoWmmKXuUsCqlZ0xA0Nslf bzEn3bJDl4ywSxxq8kY1gZ3WWTerwBQTKK0t+yoQnkJNUBBNJkVzFDiwBAQF9Lnw cdq7jyDwNa1xbG66PEpkKOGhxeflo3LrTsSMpUcOCjjkyWIlrYr28rVBxzhEqHn5 gfOd/FhuS1c=hOVY -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat support for Spring Boot 2.2.6.SP2 security update Advisory ID: RHSA-2020:3806-01 Product: Red Hat OpenShift Application Runtimes Advisory URL: https://access.redhat.com/errata/RHSA-2020:3806 Issue date: 2020-09-23 CVE Names: CVE-2020-10688 CVE-2020-10693 CVE-2020-13934 CVE-2020-13935 ==================================================================== 1. Summary: An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat support for Spring Boot provides an application platform that reduces the complexity of developing and operating applications (monoliths and microservices) for OpenShift as a containerized platform. This release of Red Hat support for Spring Boot 2.2.6.SP2 serves as a replacement for Red Hat support for Spring Boot 2.2.6.SP1, and includes security and bug fixes and enhancements. For further information, refer to the release notes linked to in the References section. Security Fix(es): * resteasy: RESTEASY003870 exception in RESTEasy can lead to a reflected XSS attack (CVE-2020-10688) * hibernate-validator: Improper input validation in the interpolation of constraint error messages (CVE-2020-10693) * tomcat: multiple requests with invalidpayload length in a WebSocket frame could lead to DoS (CVE-2020-13935) * tomcat: OutOfMemoryException caused by HTTP/2 connection leak could lead to DoS (CVE-2020-13934) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). 4. Bugs fixed (https://bugzilla.redhat.com/): 1805501 - CVE-2020-10693 hibernate-validator: Improper input validation in the interpolation of constraint error messages 1814974 - CVE-2020-10688 RESTEasy: RESTEASY003870 exception in RESTEasy can lead to a reflected XSS attack 1857024 - CVE-2020-13935 tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoS 1857040 - CVE-2020-13934 tomcat: OutOfMemoryException caused by HTTP/2 connection leak could lead to DoS 5. References: https://access.redhat.com/security/cve/CVE-2020-10688 https://access.redhat.com/security/cve/CVE-2020-10693 https://access.redhat.com/security/cve/CVE-2020-13934 https://access.redhat.com/security/cve/CVE-2020-13935 https://access.redhat.com/security/updates/classification#important https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=catRhoar.spring.boot&version=2.2.6.SP2 https://docs.redhat.com/en/documentation/red_hat_support_for_spring_boot/2.2/html-single/release_notes_for_spring_boot_2.2/index#advisories-related-to-current-release-spring-boot 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBX2t3otzjgjWX9erEAQh26RAAgcJ7EUdFjrelpODcC8VN+yGcBSPLWrhs RS9ycDoUq8nQxCjmJ7ADo2QRpPowcPY9lt7VX6AEmqVi+rI4HwagZG4nUx/NQoq0 pGtZ0mgJ/YxGdLqJnNazoYXofqBq8yr2wojT3dVJ1RENyibFMR5bPYLAWSgoxuuB t8hsP7nwQzFU4c/BuoSgp2XLpGY2LtnrRIJgvicFS47HqtdfFqoiRLqci5/FJQ4n DxbfnAL6pCtoyEKJCWsUQQ28A2ONQHErC0Y8XONZrN+eKvEV4T6Dk/Bgeoc8iSr/ E7PL0n+mnuw9xhtPjxI2rzmgPx/jfjy35tYbR7kRoOxjP87dF2E3rhGLnj7HzX0W Z/V/dTwDJYGu3ryzp7/66txYY9uBBT0vvZl01GVakSxOog39okKfgX4Os+jUJCSU IDV/8zbc7V+tAuie1JrEuv4RyUBZi39AyU1WN6nsE43/eWHmzAvEBpQJpMpDfDgj nf7lFZfYzWAVCL80C6O5/qHVD0ZkNUviTuEt6cOb29JwK5dPioYgJrlE9antECJx Tzuqk+Q02kxVzThijNvMhLAoa+bqzs4mLSY6KIcYuHUD/OOFNSqfDm5ExgduXKhR LmUVon9pk6OJqw1C9XnHXKs9yd0kRvDjBh3DBDQykCMru+OsLqq6DOvdQ/GYF7ON wZsvtSdws5U=eT/H -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.