RHSA-2021:2039: Moderate: Service Registry (container images) release and security update [1.1.1.GA]
This release of Red Hat Integration - Service registry 1.1.1.GA serves as a replacement for 1.1.0.GA, and includes the below security fixes.Security Fix(es): hibernate-core: SQL injection vulnerability when both hibernate.usesqlcomments and JPQL String literals are used (CVE-2020-25638) jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE) (CVE-2020-25649) golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash (CVE-2020-14040) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.1.1.GA
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:2039?
The severity of RHSA-2021:2039 is classified as critical due to the SQL injection vulnerability it addresses.
How do I fix RHSA-2021:2039?
To fix RHSA-2021:2039, it is recommended to upgrade to the latest version of Red Hat Integration - Service Registry.
What specific vulnerabilities are addressed in RHSA-2021:2039?
RHSA-2021:2039 addresses SQL injection vulnerabilities arising from the use of hibernate.use_sql_comments and JPQL String literals.
Which software is affected by RHSA-2021:2039?
RHSA-2021:2039 affects Red Hat Integration - Service Registry version 1.1.0.GA and earlier.
What is the impact of not addressing RHSA-2021:2039?
Failing to address RHSA-2021:2039 may expose applications to SQL injection attacks, potentially compromising data integrity and confidentiality.