First published: Tue Aug 14 2018(Updated: )
Red Hat Fuse Integration Services provides a set of tools and containerized xPaaS images that enable development, deployment, and management of integration microservices within OpenShift.<br>Security fix(es):<br><li> undertow: Client can use bogus uri in Digest authentication (CVE-2017-12196)</li> <li> spring-boot: Malicious PATCH requests submitted to servers can use specially crafted JSON data to run arbitrary Java code (CVE-2017-8046)</li> <li> spring-framework: Improper URL path validation allows for bypassing of security checks on static resources (CVE-2018-1199)</li> <li> ignite: Possible Execution of Arbitrary Code Within Deserialization Endpoints (CVE-2018-1295)</li> <li> spark: Absolute and relative pathnames allow for unintended static file disclosure (CVE-2018-9159)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.<br>The CVE-2017-12196 issue was discovered by Jan Stourac (Red Hat).
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.