First published: Thu Oct 28 2021(Updated: )
Red Hat support for Spring Boot provides an application platform that reduces the complexity of developing and operating applications (monoliths and microservices) for OpenShift as a containerized platform.<br>This release of Red Hat support for Spring Boot 2.4.9 serves as a replacement for Red Hat support for Spring Boot 2.3.10 and includes security, bug fixes, and enhancements. For more information, see the release notes listed in the References section.<br>Security Fix(es):<br><li> tomcat: Apache Tomcat HTTP/2 Request mix-up (CVE-2020-13943)</li> <li> tomcat: HTTP/2 request header mix-up (CVE-2020-17527)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2021:4012 is classified as moderate.
To fix RHSA-2021:4012, you should update to the latest version of Spring Boot as recommended in the advisory.
RHSA-2021:4012 affects specific versions of Red Hat's Spring Boot, primarily those prior to version 2.4.9.
RHSA-2021:4012 addresses vulnerabilities related to security and stability in the Spring Boot framework.
RHSA-2021:4012 is primarily applicable to environments running Red Hat OpenShift with Spring Boot applications.