RHSA-2018:2946: Moderate: Red Hat OpenShift Application Runtimes security and bug fix update
Red Hat Openshift Application Runtimes provides an application platform<br>that reduces the complexity of developing and operating applications<br>(monoliths and microservices) for OpenShift as a containerized platform.<br>The RHOAR Eclipse Vert.x 3.5.4 release serves as a replacement for RHOAR Eclipse Vert.x 3.5.3, and includes bug fixes and enhancements. For a detailed list of issues resolved in the community Eclipse Vert.x 3.5.4 release, see the release notes in the References section.<br>Security Fix(es):<br><li> vertx: WebSocket HTTP upgrade implementation holds the entire http request in memory before the handshake (CVE-2018-12541)</li> <li> vertx: API Validation XML Schemas do not forbid file system access (CVE-2018-12544)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2018:2946?
The severity of RHSA-2018:2946 is classified as moderate.
How do I fix RHSA-2018:2946?
To fix RHSA-2018:2946, update the Red Hat OpenShift Application Runtimes to the latest version provided in the advisory.
What are the risks associated with RHSA-2018:2946?
The risks associated with RHSA-2018:2946 include potential vulnerabilities that may be exploited to compromise application security.
Which versions of OpenShift Application Runtimes are affected by RHSA-2018:2946?
RHSA-2018:2946 affects specific versions of Red Hat OpenShift Application Runtimes prior to the vulnerability resolution.
When was RHSA-2018:2946 released?
RHSA-2018:2946 was released on November 28, 2018.