RHSA-2014:0400: Moderate: Red Hat JBoss Fuse 6.1.0 update
Red Hat JBoss Fuse, based on Apache ServiceMix, provides a small-footprint,flexible, open source enterprise service bus and integration platform.Security fixes:A flaw was found in the way Apache Santuario XML Security for Javavalidated XML signatures. Santuario allowed a signature to specify anarbitrary canonicalization algorithm, which would be applied to theSignedInfo XML fragment. A remote attacker could exploit this to spoof anXML signature via a specially crafted XML signature block. (CVE-2013-2172)A flaw was found in the Apache Hadoop RPC protocol. A man-in-the-middleattacker could possibly use this flaw to unilaterally disable bidirectionalauthentication between a client and a server, forcing a downgrade to simple(unidirectional) authentication. This flaw only affected users who haveenabled Hadoop's Kerberos security features. (CVE-2013-2192)It was discovered that the Spring OXM wrapper did not expose any propertyfor disabling entity resolution when using the JAXB unmarshaller. A remoteattacker could use this flaw to conduct XML External Entity (XXE) attackson web sites, and read files in the context of the user running theapplication server. (CVE-2013-4152)It was discovered that the Apache Santuario XML Security for Java projectallowed Document Type Definitions (DTDs) to be processed when applyingTransforms even when secure validation was enabled. A remote attacker coulduse this flaw to exhaust all available memory on the system, causing adenial of service. (CVE-2013-4517)It was found that the Spring MVC SourceHttpMessageConverter enabled entityresolution by default. A remote attacker could use this flaw to conduct XXEattacks on web sites, and read files in the context of the user running theapplication server. (CVE-2013-6429)The Spring JavaScript escape method insufficiently escaped some characters.Applications using this method to escape user-supplied content, which wouldbe rendered in HTML5 documents, could be exposed to cross-site scripting(XSS) flaws. (CVE-2013-6430)A denial of service flaw was found in the way Apache Commons FileUploadhandled small-sized buffers used by MultipartStream. A remote attackercould use this flaw to create a malformed Content-Type header for amultipart request, causing Apache Commons FileUpload to enter an infiniteloop when processing such an incoming request. (CVE-2014-0050)It was found that fixes for the CVE-2013-4152 and CVE-2013-6429 XXE issuesin Spring were incomplete. Spring MVC processed user-provided XML andneither disabled XML external entities nor provided an option to disablethem, possibly allowing a remote attacker to conduct XXE attacks.(CVE-2014-0054)A cross-site scripting (XSS) flaw was found in the Spring Framework whenusing Spring MVC. When the action was not specified in a Spring form, theaction field would be populated with the requested URI, allowing anattacker to inject malicious content into the form. (CVE-2014-1904)The HawtJNI Library class wrote native libraries to a predictable file namein /tmp when the native libraries were bundled in a JAR file, and no customlibrary path was specified. A local attacker could overwrite these nativelibraries with malicious versions during the window between when HawtJNIwrites them and when they are executed. (CVE-2013-2035)An information disclosure flaw was found in the way Apache Zookeeper storedthe password of an administrative user in the log files. A local user withaccess to these log files could use the exposed sensitive information togain administrative access to an application using Apache Zookeeper.(CVE-2014-0085)The CVE-2013-6430 issue was discovered by Jon Passki of Coverity SRL andArun Neelicattu of the Red Hat Security Response Team, the CVE-2013-2035issue was discovered by Florian Weimer of the Red Hat Product SecurityTeam, and the CVE-2014-0085 issue was discovered by Graeme Colman ofRed Hat.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2014:0400?
The severity of RHSA-2014:0400 is classified as moderate.
How do I fix RHSA-2014:0400?
To fix RHSA-2014:0400, you should apply the latest updates released by Red Hat for JBoss Fuse.
What vulnerabilities does RHSA-2014:0400 address?
RHSA-2014:0400 addresses a flaw in the Apache Santuario XML Security for Java that impacts XML signature validation.
Is RHSA-2014:0400 applicable to all versions of JBoss Fuse?
RHSA-2014:0400 is applicable to specific versions of JBoss Fuse that are affected by the identified vulnerability.
What are the potential impacts of not addressing RHSA-2014:0400?
Not addressing RHSA-2014:0400 could lead to potential security risks associated with improper XML signature validation.