RHSA-2019:3140: Important: Red Hat JBoss Data Virtualization 6.4.8 security update
Red Hat JBoss Data Virtualization is a lean data integration solution that provides easy, real-time, and unified data access across disparate sources to multiple applications and users. JBoss Data Virtualization makes data spread across physically distinct systems - such as multiple databases, XML files, and even Hadoop systems - appear as a set of tables in a local database.<br>This release of Red Hat JBoss Data Virtualization 6.4.8 serves as a replacement for Red Hat JBoss Data Virtualization 6.4.7, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.<br>Security Fix(es):<br><li> thrift: Improper file path sanitization in tgogenerator.cc:formatgooutput() of the go client library can allow an attacker to inject commands (CVE-2016-5397)</li> <li> tika-core: tika: Command injection in tika-server can allow remote attackers to execute arbitrary commands via crafted headers (CVE-2018-1335)</li> <li> slf4j: Deserialisation vulnerability in EventData constructor can allow for arbitrary code execution (CVE-2018-8088)</li> <li> jackson-databind: Potential information exfiltration with default typing, serialization gadget from MyBatis (CVE-2018-11307)</li> <li> libthrift: thrift: Improper Access Control grants access to files outside the webservers docroot path (CVE-2018-11798)</li> <li> jackson-databind: improper polymorphic deserialization of types from Jodd-db library (CVE-2018-12022)</li> <li> jackson-databind: improper polymorphic deserialization of types from Oracle JDBC driver (CVE-2018-12023)</li> <li> jackson-databind: arbitrary code execution in slf4j-ext class (CVE-2018-14718)</li> <li> jackson-databind: arbitrary code execution in blaze-ds-opt and blaze-ds-core classes (CVE-2018-14719)</li> <li> jackson-databind: improper polymorphic deserialization in axis2-transport-jms class (CVE-2018-19360)</li> <li> jackson-databind: improper polymorphic deserialization in openjpa class (CVE-2018-19361)</li> <li> jackson-databind: improper polymorphic deserialization in jboss-common-core class (CVE-2018-19362)</li> <li> zookeeper: Information disclosure in Apache ZooKeeper (CVE-2019-0201)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:3140?
The severity of RHSA-2019:3140 is classified as moderate.
How do I fix RHSA-2019:3140?
To fix RHSA-2019:3140, you should update your JBoss Data Virtualization to the latest patched version.
What versions of JBoss Data Virtualization are affected by RHSA-2019:3140?
RHSA-2019:3140 affects various versions of JBoss Data Virtualization prior to the fix release.
What are the potential risks of not addressing RHSA-2019:3140?
Failing to address RHSA-2019:3140 may expose your system to vulnerabilities that could be exploited by attackers.
Is there a workaround for RHSA-2019:3140 before a patch can be implemented?
Currently, there are no specific workarounds suggested for RHSA-2019:3140, and it is recommended to apply the patch.