First published: Tue Dec 04 2018(Updated: )
Red Hat Fuse enables integration experts, application developers, and business users to collaborate and independently develop connected solutions.<br>Fuse is part of an agile integration solution. Its distributed approach allows teams to deploy integrated services where required. The API-centric, container-based architecture decouples services so they can be created, extended, and deployed independently.<br>This release of Red Hat Fuse 7.2 serves as a replacement for Red Hat Fuse 7.1, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.<br>Security Fix(es):<br><li> xmlrpc: Deserialization of untrusted Java object through <ex:serializable> tag (CVE-2016-5003)</li> <li> tomcat: A bug in the UTF-8 decoder can lead to DoS (CVE-2018-1336)</li> <li> ignite: Improper deserialization allows for code execution via GridClientJdkMarshaller endpoint (CVE-2018-8018)</li> <li> apache-cxf: TLS hostname verification does not work correctly with com.sun.net.ssl.* (CVE-2018-8039)</li> <li> xmlrpc: XML external entity vulnerability SSRF via a crafted DTD (CVE-2016-5002)</li> <li> undertow: Client can use bogus uri in Digest authentication (CVE-2017-12196)</li> <li> spring-data-commons: XXE with Spring Data’s XMLBeam integration (CVE-2018-1259)</li> <li> kafka: Users can perform Broker actions via crafted fetch requests, interfering with data replication and causing data lass (CVE-2018-1288)</li> <li> tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins (CVE-2018-8014)</li> <li> camel-mail: path traversal vulnerability (CVE-2018-8041)</li> <li> vertx: Improper neutralization of CRLF sequences allows remote attackers to inject arbitrary HTTP response headers (CVE-2018-12537)</li> <li> spring-framework: ReDoS Attack with spring-messaging (CVE-2018-1257)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.<br>Red Hat would like to thank Eedo Shapira (GE Digital) for reporting CVE-2018-8041. The CVE-2017-12196 issue was discovered by Jan Stourac (Red Hat).
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.