First published: Wed Oct 17 2018(Updated: )
Red Hat Fuse Integration Services provides a set of tools and containerized xPaaS images that enable development, deployment, and management of integration microservices within OpenShift.<br>Security fix(es):<br><li> jackson-databind: incomplete fix for CVE-2017-7525 permits unsafe serialization via c3p0 libraries (CVE-2018-7489)</li> <li> spring-framework: Address partial fix for CVE-2018-1270 (CVE-2018-1275)</li> <li> spring-framework: Directory traversal vulnerability with static resources on Windows filesystems (CVE-2018-1271)</li> <li> spring-framework: Possible RCE via spring messaging (CVE-2018-1270)</li> <li> spring-security-oauth: remote code execution in the authorization process (CVE-2018-1260)</li> <li> tomcat: A bug in the UTF-8 decoder can lead to DoS (CVE-2018-1336)</li> <li> tomcat: Incorrect handling of empty string URL in security constraints can lead to unintended exposure of resources (CVE-2018-1304)</li> <li> tomcat: Late application of security constraints can lead to resource exposure for unauthorised users (CVE-2018-1305)</li> <li> tomcat: Remote Code Execution bypass for CVE-2017-12615 (CVE-2017-12617)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.