Twenty Year Anniversary

Red Hat Security Advisory 2018-1809-01

Red Hat Security Advisory 2018-1809-01
Posted Jun 7, 2018
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2018-1809-01 - Red Hat Openshift Application Runtimes provides an application platform that reduces the complexity of developing and operating applications for OpenShift as a containerized platform. This release of RHOAR Spring Boot 1.5.13 serves as a replacement for RHOAR Spring Boot 1.5.12, and includes bug fixes and enhancements. For further information, refer to the Release Notes linked to in the References section. Issues addressed include code execution and denial of service vulnerabilities.

tags | advisory, denial of service, vulnerability, code execution
systems | linux, redhat
advisories | CVE-2018-1257, CVE-2018-1259, CVE-2018-1260
MD5 | 3a71a59b4993487c49e2172e7b6e7359

Red Hat Security Advisory 2018-1809-01

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
Red Hat Security Advisory

Synopsis: Important: Red Hat OpenShift Application Runtimes Spring Boot security and bug fix update
Advisory ID: RHSA-2018:1809-01
Product: Red Hat OpenShift Application Runtimes
Advisory URL: https://access.redhat.com/errata/RHSA-2018:1809
Issue date: 2018-06-07
CVE Names: CVE-2018-1257 CVE-2018-1259 CVE-2018-1260
=====================================================================

1. Summary:

An update is now available for Red Hat OpenShift Application Runtimes.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Description:

Red Hat Openshift Application Runtimes provides an application platform
that reduces the complexity of developing and operating applications
(monoliths and microservices) for OpenShift as a containerized platform.

This release of RHOAR Spring Boot 1.5.13 serves as a replacement for RHOAR
Spring Boot 1.5.12, and includes bug fixes and enhancements. For further
information, refer to the Release Notes linked to in the References
section.

Security Fix(es):

* spring-messaging: ReDoS Attack with spring-messaging (CVE-2018-1257)

* spring-data: XXE with Spring Dataas XMLBeam integration (CVE-2018-1259)

* spring-security-oauth2: Remote Code Execution with spring-security-oauth2
(CVE-2018-1260)

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.

3. Solution:

Before applying the update, back up your existing installation, including
all applications, configuration files, databases and database settings, and
so on.

The References section of this erratum contains a download link (you must
log in to download the update).

4. Bugs fixed (https://bugzilla.redhat.com/):

1578578 - CVE-2018-1257 spring-framework: ReDoS Attack with spring-messaging
1578902 - CVE-2018-1259 spring-data-commons: XXE with Spring Dataas XMLBeam integration
1584376 - CVE-2018-1260 spring-security-oauth: remote code execution in the authorization process

5. References:

https://access.redhat.com/security/cve/CVE-2018-1257
https://access.redhat.com/security/cve/CVE-2018-1259
https://access.redhat.com/security/cve/CVE-2018-1260
https://access.redhat.com/security/updates/classification/#important
https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=catRhoar.spring.boot&downloadType=distributions&version=1.5.13
https://access.redhat.com/documentation/en-us/red_hat_openshift_application_runtimes/1/html-single/red_hat_openshift_application_runtimes_release_notes/

6. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2018 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBWxjsW9zjgjWX9erEAQhfEQ/+PTikYmX1OgClszizb9ySdvw81KmHoXPl
g5YBhWPzXTlZgHwC27wrUlB9Z8GqGgKTcYnyrttHQLFzkvUBiD6su8rRswEYzKwo
N1zYYOaWpXAFKSYTxiMEaVyUIDqFicLRRZ0aYM85nqpds0Bbg3Tg9OTCvp5L2XNU
Apmj78FynXibXTBx5UJ/qby6L82GaFyHjThjRQNfpsxz2SY6B3gFyUQmvVmqW7wQ
XGLAIQVvSR5Ot5spBRa1wDutL4mNAYYlBr2zLbP/KJbZhYdQxAccBTT2wD5dyiLo
+TC3mtMfR+OnyaEQx8ujPY4so8YxMMrKs7NZ2nCLDm20YjRCguRWK/i/pYJm0yBf
eu79WyRlRbNVh/GR4FuGAl5zk6p10+dLEBlRALuL8d+aeyywkb7p3UqUSW2/KpEL
k4ZlpzwA2IOuTfk7RNi2TrzJzdQ/HvHHjAs0o+Svq4kOgAEKnxBSBLZmxuVd06l7
jxRwHo/AZ83JSxEczAAB4NavEYCNFKxJCK4o3p2C2oZIVxPkqWiPBo9JGYvkwXdL
9wkc7EE2+ZQA6zxdYEUf43wU9Mc9zTOyr/KupJXcn+osPCQzmj0fKSVAoe492IBX
EblswgDjFLhRR836ocazA4GcyYMUgSGmIb93CfFZytUR2csR1HDlQ7azWklbnUIM
mU0w0GxsQgU=
=FqMM
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

September 2018

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    1 Files
  • 2
    Sep 2nd
    3 Files
  • 3
    Sep 3rd
    15 Files
  • 4
    Sep 4th
    15 Files
  • 5
    Sep 5th
    18 Files
  • 6
    Sep 6th
    18 Files
  • 7
    Sep 7th
    15 Files
  • 8
    Sep 8th
    2 Files
  • 9
    Sep 9th
    2 Files
  • 10
    Sep 10th
    16 Files
  • 11
    Sep 11th
    17 Files
  • 12
    Sep 12th
    15 Files
  • 13
    Sep 13th
    29 Files
  • 14
    Sep 14th
    21 Files
  • 15
    Sep 15th
    3 Files
  • 16
    Sep 16th
    1 Files
  • 17
    Sep 17th
    15 Files
  • 18
    Sep 18th
    16 Files
  • 19
    Sep 19th
    29 Files
  • 20
    Sep 20th
    18 Files
  • 21
    Sep 21st
    5 Files
  • 22
    Sep 22nd
    2 Files
  • 23
    Sep 23rd
    2 Files
  • 24
    Sep 24th
    15 Files
  • 25
    Sep 25th
    69 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2018 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close