First published: Mon Aug 31 2020(Updated: )
Red Hat JBoss Enterprise Application Platform CD20 is a platform for Java applications based on the WildFly application runtime.<br>This release of Red Hat JBoss Enterprise Application Platform CD20 includes bug fixes and enhancements. <br>Security Fix(es):<br><li> jsf-impl: mojarra: Path traversal in ResourceManager.java:getLocalePrefix() via the loc parameter (CVE-2018-14371)</li> <li> jackson-mapper-asl: XML external entity similar to CVE-2016-3720 (CVE-2019-10172)</li> <li> hibernate-core: hibernate: SQL injection issue in Hibernate ORM (CVE-2019-14900)</li> <li> jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution (CVE-2020-10673)</li> <li> dom4j: XML External Entity vulnerability in default SAX parser (CVE-2020-10683)</li> <li> undertow: Memory exhaustion issue in HttpReadListener via "Expect: 100-continue" header (CVE-2020-10705)</li> <li> wildfly-elytron: session fixation when using FORM authentication (CVE-2020-10714)</li> <li> undertow: invalid HTTP request with large chunk size (CVE-2020-10719)</li> <li> wildfly: unsafe deserialization in Wildfly Enterprise Java Beans (CVE-2020-10740)</li> <li> netty: compression/decompression codecs don't enforce limits on buffer allocation sizes (CVE-2020-11612)</li> <li> wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain (CVE-2020-1719)</li> <li> cxf-core: cxf: JMX integration is vulnerable to a MITM attack (CVE-2020-1954)</li> <li> jsf-impl: Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371 (CVE-2020-6950)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.