First published: Tue Apr 12 2022(Updated: )
Red Hat support for Spring Boot provides an application platform that reduces the complexity of developing and operating applications (monoliths and microservices) for OpenShift as a containerized platform.<br>This release of Red Hat support for Spring Boot 2.5.10 serves as a replacement for Red Hat support for Spring Boot 2.4.9, and includes bug fixes and enhancements. For more information, see the release notes listed in the References section.<br>Security Fix(es):<br><li> undertow: client side invocation timeout raised when calling over HTTP2 (CVE-2021-3859)</li> <li> tomcat: Infinite loop while reading an unexpected TLS packet when using OpenSSL JSSE engine (CVE-2021-41079)</li> <li> tomcat: OutOfMemoryError caused by HTTP upgrade connection leak could lead to DoS (CVE-2021-42340)</li> <li> undertow: HTTP2SourceChannel fails to write final frame under some circumstances may lead to DoS (CVE-2021-3597)</li> <li> undertow: potential security issue in flow control over HTTP/2 may lead to DOS (CVE-2021-3629)</li> <li> wildfly-elytron: possible timing attack in ScramServer (CVE-2021-3642)</li> <li> tomcat: HTTP request smuggling when used with a reverse proxy (CVE-2021-33037)</li> <li> resteasy: Error message exposes endpoint class information (CVE-2021-20289)</li> <li> tomcat: JNDI realm authentication weakness (CVE-2021-30640)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
<2.5.10 | ||
<2.4.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:1179 is considered moderate.
To fix RHSA-2022:1179, you need to update to the latest version of Red Hat support for Spring Boot 2.5.10.
RHSA-2022:1179 addresses vulnerabilities pertaining to Spring Boot that could impact application security.
RHSA-2022:1179 affects applications running on the Red Hat OpenShift container platform utilizing Spring Boot.
RHSA-2022:1179 was released on February 2, 2022.