RHSA-2018:2939: Critical: Red Hat FIS 2.0 on Fuse 6.3.0 R8 security and bug fix update
Red Hat Fuse Integration Services provides a set of tools and containerized xPaaS images that enable development, deployment, and management of integration microservices within OpenShift.Security fix(es): jackson-databind: incomplete fix for CVE-2017-7525 permits unsafe serialization via c3p0 libraries (CVE-2018-7489) spring-framework: Address partial fix for CVE-2018-1270 (CVE-2018-1275) spring-framework: Directory traversal vulnerability with static resources on Windows filesystems (CVE-2018-1271) spring-framework: Possible RCE via spring messaging (CVE-2018-1270) spring-security-oauth: remote code execution in the authorization process (CVE-2018-1260) tomcat: A bug in the UTF-8 decoder can lead to DoS (CVE-2018-1336) tomcat: Incorrect handling of empty string URL in security constraints can lead to unintended exposure of resources (CVE-2018-1304) tomcat: Late application of security constraints can lead to resource exposure for unauthorised users (CVE-2018-1305) tomcat: Remote Code Execution bypass for CVE-2017-12615 (CVE-2017-12617) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2018:2939?
The severity of RHSA-2018:2939 is considered to be moderate, primarily due to issues with jackson-databind related to CVE-2017-7525.
How do I fix RHSA-2018:2939?
To fix RHSA-2018:2939, you should apply the latest updates for Red Hat Fuse Integration Services that address the jackson-databind vulnerability.
What vulnerabilities are addressed in RHSA-2018:2939?
RHSA-2018:2939 addresses an incomplete fix for CVE-2017-7525 in jackson-databind, which can lead to unsafe deserialization issues.
What versions are affected by RHSA-2018:2939?
RHSA-2018:2939 affects various versions of Red Hat Fuse Integration Services before the security update.
Is there a timeline for the release of a patch for RHSA-2018:2939?
The patch for RHSA-2018:2939 has been released in line with Red Hat's regular update schedule.