RHSA-2019:2998: Important: Red Hat OpenShift Application Runtimes Thorntail 2.5.0 security & bug fix update
Red Hat OpenShift Application Runtimes provides an application platform that reduces the complexity of developing and operating applications (monoliths and microservices) for OpenShift as a containerized platform.<br>This release of RHOAR Thorntail 2.5.0 serves as a replacement for RHOAR Thorntail 2.4.0, and includes security and bug fixes and enhancements. For further information, refer to the release notes linked to in the References section.<br>Security Fix(es):<br><li> keycloak: session hijack using the user access token (CVE-2019-3868)</li> <li> undertow: leak credentials to log files UndertowLogger.REQUESTLOGGER.undertowRequestFailed (CVE-2019-3888)</li> <li> undertow: Information leak in requests for directories without trailing slashes (CVE-2019-10184)</li> <li> jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files on the server (CVE-2019-12086)</li> <li> jackson-databind: failure to block the logback-core class from polymorphic deserialization leading to remote code execution (CVE-2019-12384)</li> <li> undertow: DEBUG log for io.undertow.request.security if enabled leaks credentials to log files (CVE-2019-10212)</li> <li> jackson-databind: default typing mishandling leading to remote code execution (CVE-2019-14379)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:2998?
The severity of RHSA-2019:2998 is classified as moderate.
How do I fix RHSA-2019:2998?
To fix RHSA-2019:2998, you need to update the Red Hat OpenShift Application Runtimes to the latest version as indicated in the advisory.
What products are affected by RHSA-2019:2998?
RHSA-2019:2998 affects Red Hat OpenShift Application Runtimes, specifically those using Thorntail 2.5.0.
What is the impact of not addressing RHSA-2019:2998?
Not addressing RHSA-2019:2998 could lead to potential vulnerabilities and instability in applications running on the affected platforms.
Is there a workaround for RHSA-2019:2998?
There is no specific workaround for RHSA-2019:2998; upgrading to the recommended version is the advised action.