First published: Thu Sep 09 2021(Updated: )
Red Hat support for Spring Boot provides an application platform that reduces the complexity of developing and operating applications (monoliths and microservices) for OpenShift as a containerized platform.<br>This release of Red Hat support for Spring Boot 2.3.10 serves as a replacement for Red Hat support for Spring Boot 2.3.6, and includes security and bug fixes and enhancements. For more information, see the release notes listed in the References section.<br>Security Fix(es):<br><li> undertow: special character in query results in server errors (CVE-2020-27782)</li> <li> undertow: buffer leak on incoming websocket PONG message may lead to DoS (CVE-2021-3690)</li> <li> tomcat: Information disclosure when using NTFS file system (CVE-2021-24122)</li> <li> tomcat: Request mix-up with h2c (CVE-2021-25122)</li> <li> tomcat: Incomplete fix for CVE-2020-9484 (RCE via session persistence) (CVE-2021-25329)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.