RHSA-2021:1515: Important: Openshift Logging Bug Fix Release (5.0.3)
Openshift Logging Bug Fix Release (5.0.3)Security Fix(es): jackson-databind: arbitrary code execution in slf4j-ext class (CVE-2018-14718) jackson-databind: arbitrary code execution in blaze-ds-opt and blaze-ds-core classes (CVE-2018-14719) jackson-databind: improper polymorphic deserialization in axis2-transport-jms class (CVE-2018-19360) jackson-databind: improper polymorphic deserialization in openjpa class (CVE-2018-19361) jackson-databind: improper polymorphic deserialization in jboss-common-core class (CVE-2018-19362) jackson-databind: default typing mishandling leading to remote code execution (CVE-2019-14379) jackson-databind: Serialization gadgets in com.pastdev.httpcomponents.configuration.JndiConfiguration (CVE-2020-24750) jackson-databind: mishandles the interaction between serialization gadgets and typing, related toorg.apache.commons.dbcp2.datasources.PerUserPoolDataSource (CVE-2020-35490) jackson-databind: mishandles the interaction between serialization gadgets and typing, related toorg.apache.commons.dbcp2.datasources.SharedPoolDataSource (CVE-2020-35491) jackson-databind: mishandles the interaction between serialization gadgets and typing, related tocom.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool(CVE-2020-35728) jackson-databind: mishandles the interaction between serialization gadgets and typing, related tooadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS (CVE-2020-36179) jackson-databind: mishandles the interaction between serialization gadgets and typing, related toorg.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS (CVE-2020-36180) jackson-databind: mishandles the interaction between serialization gadgets and typing, related toorg.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS (CVE-2020-36181) jackson-databind: mishandles the interaction between serialization gadgets and typing, related toorg.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS (CVE-2020-36182) jackson-databind: mishandles the interaction between serialization gadgets and typing, related toorg.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool (CVE-2020-36183) jackson-databind: mishandles the interaction between serialization gadgets and typing, related toorg.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource(CVE-2020-36184) jackson-databind: mishandles the interaction between serialization gadgets and typing, related toorg.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource(CVE-2020-36185) jackson-databind: mishandles the interaction between serialization gadgets and typing, related toorg.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource(CVE-2020-36186) jackson-databind: mishandles the interaction between serialization gadgets and typing, related toorg.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource(CVE-2020-36187) jackson-databind: mishandles the interaction between serialization gadgets and typing, related tocom.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource(CVE-2020-36188) jackson-databind: mishandles the interaction between serialization gadgets and typing, related tocom.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource (CVE-2020-36189) jackson-databind: mishandles the interaction between serialization gadgets and typing, related to javax.swing (CVE-2021-20190) jackson-databind: exfiltration/XXE in some JDK classes (CVE-2018-14720) jackson-databind: server-side request forgery (SSRF) in axis2-jaxws class (CVE-2018-14721) golang: data race in certain net/http servers including ReverseProxy can lead to DoS (CVE-2020-15586) golang: ReadUvarint and ReadVarint can read an unlimited number of bytes from invalid inputs (CVE-2020-16845) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:1515?
The severity of RHSA-2021:1515 is classified as important.
How do I fix RHSA-2021:1515?
To fix RHSA-2021:1515, apply the updates provided in the security advisory.
What vulnerabilities are addressed in RHSA-2021:1515?
RHSA-2021:1515 addresses arbitrary code execution vulnerabilities in jackson-databind classes.
Is RHSA-2021:1515 applicable to my system?
RHSA-2021:1515 is applicable if your system uses the versions of OpenShift Logging affected by the advisory.
What components are affected by RHSA-2021:1515?
RHSA-2021:1515 affects components that rely on specific jackson-databind versions that have security issues.