RHSA-2022:8652: Important: Red Hat Fuse 7.11.1 release and security update
This release of Red Hat Fuse 7.11.1 serves as a replacement for Red Hat Fuse 7.11 and includes bug fixes and enhancements, which are documented in the Release Notes document linked in the References.Security Fix(es): hsqldb: Untrusted input may lead to RCE attack [fuse-7] (CVE-2022-41853) io.hawt-hawtio-online: bootstrap: XSS in the tooltip or popover data-template attribute [fuse-7] (CVE-2019-8331) io.hawt-project: bootstrap: XSS in the tooltip or popover data-template attribute [fuse-7] (CVE-2019-8331) wildfly: incorrect JBOSSLOCALUSER challenge location may lead to giving access to all the local users [fuse-7] (CVE-2021-3717) json-smart: Denial of Service in JSONParserByteArray function [fuse-7] (CVE-2021-31684) io.hawt-hawtio-integration: minimist: prototype pollution [fuse-7] (CVE-2021-44906) urijs: Authorization Bypass Through User-Controlled Key [fuse-7] (CVE-2022-0613) http2-server: Invalid HTTP/2 requests cause DoS [fuse-7] (CVE-2022-2048) snakeyaml: Denial of Service due to missing nested depth limitation for collections [fuse-7] (CVE-2022-25857) urijs: Leading white space bypasses protocol validation [fuse-7] (CVE-2022-24723) Moment.js: Path traversal in moment.locale [fuse-7] (CVE-2022-24785) netty: world readable temporary file containing sensitive data [fuse-7] (CVE-2022-24823) jdbc-postgresql: postgresql: SQL Injection in ResultSet.refreshRow() with malicious column names [fuse-7] (CVE-2022-31197) commons-configuration2: apache-commons-configuration: Apache Commons Configuration insecure interpolation defaults [fuse-7] (CVE-2022-33980) commons-text: apache-commons-text: variable interpolation RCE [fuse-7] (CVE-2022-42889) undertow: Large AJP request may cause DoS [fuse-7] (CVE-2022-2053) moment: inefficient parsing algorithm resulting in DoS [fuse-7] (CVE-2022-31129) snakeyaml: Uncaught exception in org.yaml.snakeyaml.composer.Composer.composeSequenceNode [fuse-7] (CVE-2022-38749) For more details about the security issues, including the impact, CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:8652?
The severity of RHSA-2022:8652 is classified as critical due to the risk of remote code execution.
How do I fix RHSA-2022:8652?
To fix RHSA-2022:8652, you should upgrade to Red Hat Fuse version 7.11.1 or later.
What vulnerabilities does RHSA-2022:8652 address?
RHSA-2022:8652 addresses an untrusted input vulnerability in hsqldb that may lead to RCE attacks.
Which versions of Red Hat Fuse are affected by RHSA-2022:8652?
Versions of Red Hat Fuse prior to 7.11.1 are affected by the vulnerabilities addressed in RHSA-2022:8652.
Why is it important to address RHSA-2022:8652?
It is important to address RHSA-2022:8652 to prevent potential remote code execution that could compromise the security of your systems.