First published: Wed Mar 31 2021(Updated: )
This release of Red Hat build of Eclipse Vert.x 4.0.3 includes security updates, bug fixes, and enhancements. For more information, see the release notes listed in the References section.<br>Security Fix(es):<br><li> netty: Information disclosure via the local system temporary directory (CVE-2021-21290)</li> <li> netty: possible request smuggling in HTTP/2 due missing validation (CVE-2021-21295)</li> For more details about the security issues and their impact, the CVSS score, acknowledgements, and other related information, see the CVE pages listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Vert.x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2021:0943 addresses information disclosure vulnerabilities in the netty component of Eclipse Vert.x.
To fix RHSA-2021:0943, you should update to the latest version of the Red Hat build of Eclipse Vert.x provided in the advisory.
The severity of RHSA-2021:0943 is classified as moderate.
RHSA-2021:0943 affects the Red Hat build of Eclipse Vert.x version 4.0.3.
No specific workaround is provided for RHSA-2021:0943; the recommended action is to apply the security update.