First published: Mon Jun 15 2020(Updated: )
Red Hat JBoss Enterprise Application Platform CD18 is a platform for Java applications based on the WildFly application runtime.<br>This release of Red Hat JBoss Enterprise Application Platform CD18 includes bug fixes and enhancements. <br>Security Fix(es):<br><li> jackson-databind: Serialization gadgets in org.springframework:spring-aop (CVE-2020-11619)</li> <li> jackson-databind: Serialization gadgets in commons-jelly:commons-jelly (CVE-2020-11620)</li> <li> wildfly: Race condition on PID file allows for termination of arbitrary processes by local users (CVE-2019-3805)</li> <li> undertow: HTTP/2: large amount of data requests leads to denial of service (CVE-2019-9511)</li> <li> undertow: HTTP/2: flood using HEADERS frames results in unbounded memory growth (CVE-2019-9514)</li> <li> undertow: HTTP/2: flood using SETTINGS frames results in unbounded memory growth (CVE-2019-9515)</li> <li> undertow: HTTP/2: flood using PING frames results in unbounded memory growth (CVE-2019-9512)</li> <li> wildfly-core: Incorrect privileges for 'Monitor', 'Auditor' and 'Deployer' user by default (CVE-2019-14838)</li> <li> undertow: Memory Leak in Undertow HttpOpenListener due to holding remoting connections indefinitely (CVE-2019-19343)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.