Twenty Year Anniversary

Red Hat Security Advisory 2018-1809-01

Red Hat Security Advisory 2018-1809-01
Posted Jun 7, 2018
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2018-1809-01 - Red Hat Openshift Application Runtimes provides an application platform that reduces the complexity of developing and operating applications for OpenShift as a containerized platform. This release of RHOAR Spring Boot 1.5.13 serves as a replacement for RHOAR Spring Boot 1.5.12, and includes bug fixes and enhancements. For further information, refer to the Release Notes linked to in the References section. Issues addressed include code execution and denial of service vulnerabilities.

tags | advisory, denial of service, vulnerability, code execution
systems | linux, redhat
advisories | CVE-2018-1257, CVE-2018-1259, CVE-2018-1260
MD5 | 3a71a59b4993487c49e2172e7b6e7359

Red Hat Security Advisory 2018-1809-01

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
Red Hat Security Advisory

Synopsis: Important: Red Hat OpenShift Application Runtimes Spring Boot security and bug fix update
Advisory ID: RHSA-2018:1809-01
Product: Red Hat OpenShift Application Runtimes
Advisory URL: https://access.redhat.com/errata/RHSA-2018:1809
Issue date: 2018-06-07
CVE Names: CVE-2018-1257 CVE-2018-1259 CVE-2018-1260
=====================================================================

1. Summary:

An update is now available for Red Hat OpenShift Application Runtimes.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Description:

Red Hat Openshift Application Runtimes provides an application platform
that reduces the complexity of developing and operating applications
(monoliths and microservices) for OpenShift as a containerized platform.

This release of RHOAR Spring Boot 1.5.13 serves as a replacement for RHOAR
Spring Boot 1.5.12, and includes bug fixes and enhancements. For further
information, refer to the Release Notes linked to in the References
section.

Security Fix(es):

* spring-messaging: ReDoS Attack with spring-messaging (CVE-2018-1257)

* spring-data: XXE with Spring Dataas XMLBeam integration (CVE-2018-1259)

* spring-security-oauth2: Remote Code Execution with spring-security-oauth2
(CVE-2018-1260)

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.

3. Solution:

Before applying the update, back up your existing installation, including
all applications, configuration files, databases and database settings, and
so on.

The References section of this erratum contains a download link (you must
log in to download the update).

4. Bugs fixed (https://bugzilla.redhat.com/):

1578578 - CVE-2018-1257 spring-framework: ReDoS Attack with spring-messaging
1578902 - CVE-2018-1259 spring-data-commons: XXE with Spring Dataas XMLBeam integration
1584376 - CVE-2018-1260 spring-security-oauth: remote code execution in the authorization process

5. References:

https://access.redhat.com/security/cve/CVE-2018-1257
https://access.redhat.com/security/cve/CVE-2018-1259
https://access.redhat.com/security/cve/CVE-2018-1260
https://access.redhat.com/security/updates/classification/#important
https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=catRhoar.spring.boot&downloadType=distributions&version=1.5.13
https://access.redhat.com/documentation/en-us/red_hat_openshift_application_runtimes/1/html-single/red_hat_openshift_application_runtimes_release_notes/

6. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2018 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBWxjsW9zjgjWX9erEAQhfEQ/+PTikYmX1OgClszizb9ySdvw81KmHoXPl
g5YBhWPzXTlZgHwC27wrUlB9Z8GqGgKTcYnyrttHQLFzkvUBiD6su8rRswEYzKwo
N1zYYOaWpXAFKSYTxiMEaVyUIDqFicLRRZ0aYM85nqpds0Bbg3Tg9OTCvp5L2XNU
Apmj78FynXibXTBx5UJ/qby6L82GaFyHjThjRQNfpsxz2SY6B3gFyUQmvVmqW7wQ
XGLAIQVvSR5Ot5spBRa1wDutL4mNAYYlBr2zLbP/KJbZhYdQxAccBTT2wD5dyiLo
+TC3mtMfR+OnyaEQx8ujPY4so8YxMMrKs7NZ2nCLDm20YjRCguRWK/i/pYJm0yBf
eu79WyRlRbNVh/GR4FuGAl5zk6p10+dLEBlRALuL8d+aeyywkb7p3UqUSW2/KpEL
k4ZlpzwA2IOuTfk7RNi2TrzJzdQ/HvHHjAs0o+Svq4kOgAEKnxBSBLZmxuVd06l7
jxRwHo/AZ83JSxEczAAB4NavEYCNFKxJCK4o3p2C2oZIVxPkqWiPBo9JGYvkwXdL
9wkc7EE2+ZQA6zxdYEUf43wU9Mc9zTOyr/KupJXcn+osPCQzmj0fKSVAoe492IBX
EblswgDjFLhRR836ocazA4GcyYMUgSGmIb93CfFZytUR2csR1HDlQ7azWklbnUIM
mU0w0GxsQgU=
=FqMM
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

Want To Donate?


Bitcoin: 18PFeCVLwpmaBuQqd5xAYZ8bZdvbyEWMmU

File Archive:

July 2018

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    1 Files
  • 2
    Jul 2nd
    26 Files
  • 3
    Jul 3rd
    15 Files
  • 4
    Jul 4th
    11 Files
  • 5
    Jul 5th
    13 Files
  • 6
    Jul 6th
    4 Files
  • 7
    Jul 7th
    4 Files
  • 8
    Jul 8th
    1 Files
  • 9
    Jul 9th
    16 Files
  • 10
    Jul 10th
    15 Files
  • 11
    Jul 11th
    32 Files
  • 12
    Jul 12th
    22 Files
  • 13
    Jul 13th
    15 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2018 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close