RHSA-2021:3425: Important: Red Hat support for Spring Boot 2.3.10 security update
Red Hat support for Spring Boot provides an application platform that reduces the complexity of developing and operating applications (monoliths and microservices) for OpenShift as a containerized platform.This release of Red Hat support for Spring Boot 2.3.10 serves as a replacement for Red Hat support for Spring Boot 2.3.6, and includes security and bug fixes and enhancements. For more information, see the release notes listed in the References section.Security Fix(es): undertow: special character in query results in server errors (CVE-2020-27782) undertow: buffer leak on incoming websocket PONG message may lead to DoS (CVE-2021-3690) tomcat: Information disclosure when using NTFS file system (CVE-2021-24122) tomcat: Request mix-up with h2c (CVE-2021-25122) tomcat: Incomplete fix for CVE-2020-9484 (RCE via session persistence) (CVE-2021-25329) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:3425?
The severity of RHSA-2021:3425 is classified as important due to potential security vulnerabilities in Spring Boot.
How do I fix RHSA-2021:3425?
To fix RHSA-2021:3425, you should update to the patched version of Spring Boot 2.3.10 provided by Red Hat.
What does RHSA-2021:3425 address?
RHSA-2021:3425 addresses security vulnerabilities in the Spring Boot framework impacting application security.
Which applications are affected by RHSA-2021:3425?
Applications using Spring Boot 2.3.x are affected by the vulnerabilities addressed in RHSA-2021:3425.
Is there a workaround for RHSA-2021:3425?
There are no recommended workarounds for RHSA-2021:3425; updating to the latest version is the advised action.