A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.
The REST compare API has buffer leak issue in RHDG, and I have confirmed that "OutOfMemoryError: Direct buffer memory" can occur when sending a request with some extent size of POST data (like 1MiB) to the REST API continually.
As the REST endpoint is secured (= authentication is required) by default in RHDG, it's not possible for anonymous attackers to utilize this issue. However, a malicious user can utilize this issue for DoS attack. Hence.
Important: Red Hat Data Grid 8.5.3 security update
Important: Red Hat Data Grid 8.5.2 security update
It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.
A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a denial of service. The highest threat from this vulnerability is to system availability.
Moderate: Red Hat Data Grid 8.4.7 security update
Important: Red Hat Data Grid 8.4.6 security update
Important: Red Hat Data Grid 8.4.5 security update
Red Hat Data Grid is an in-memory, distributed, NoSQL datastore solution. It increases application response times and allows for dramatically improving performance while providing availability, reliability, and elastic scale.Data Grid 8.4.2 replaces Data Grid 8.4.1 and includes bug fixes and enhancements. Find out more about Data Grid 8.4.2 in the Release Notes[3].Security Fix(es): okhttp: information disclosure via improperly used cryptographic function [jdg-8] (CVE-2021-0341) EMBARGOED infinispan-server-rest: Improper Error Handling [jdg-8] EMBARGOED infinispan-server-rest: Missing HTTP security headers [jdg-8] For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Red Hat Data Grid is an in-memory, distributed, NoSQL datastore solution. It increases application response times and allows for dramatically improving performance while providing availability, reliability, and elastic scale.<br>Data Grid 8.2.2 replaces Data Grid 8.2.1 and includes bug fixes and enhancements. Find out more about Data Grid 8.2.2 in the Release Notes [3].<br>Security Fix(es):<br><li> log4j-core: Remote code execution in Log4j 2.x when logs contain an attacker-controlled string value (CVE-2021-44228)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Red Hat Data Grid is a distributed, in-memory data store.<br>This release of Red Hat Data Grid 8.2.0 serves as a replacement for Red Hat Data Grid 8.1.1, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.<br>Security Fix(es):<br><li> Infinispan: Authentication bypass on REST endpoints when using DIGEST authentication mechanism (CVE-2021-31917)</li> <li> XStream: Unsafe deserizaliation of javax.sql.rowset.BaseRowSet (CVE-2021-21344)</li> <li> XStream: Unsafe deserizaliation of com.sun.corba.se.impl.activation.ServerTableEntry (CVE-2021-21345)</li> <li> XStream: Unsafe deserizaliation of sun.swing.SwingLazyValue (CVE-2021-21346)</li> <li> XStream: Unsafe deserizaliation of com.sun.tools.javac.processing.JavacProcessingEnvironment NameProcessIterator (CVE-2021-21347)</li> <li> XStream: Unsafe deserizaliation of com.sun.org.apache.bcel.internal.util.ClassLoader (CVE-2021-21350)</li> <li> Infinispan: Actions with effects should not be permitted via GET requests using REST API (CVE-2020-10771)</li> <li> XStream: Server-Side Forgery Request vulnerability can be activated when unmarshalling (CVE-2020-26258)</li> <li> XStream: arbitrary file deletion on the local host when unmarshalling (CVE-2020-26259)</li> <li> netty: Information disclosure via the local system temporary directory (CVE-2021-21290)</li> <li> netty: possible request smuggling in HTTP/2 due missing validation (CVE-2021-21295)</li> <li> XStream: allow a remote attacker to cause DoS only by manipulating the processed input stream (CVE-2021-21341)</li> <li> XStream: SSRF via crafted input stream (CVE-2021-21342)</li> <li> XStream: arbitrary file deletion on the local host via crafted input stream (CVE-2021-21343)</li> <li> XStream: ReDoS vulnerability (CVE-2021-21348)</li> <li> XStream: SSRF can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host (CVE-2021-21349)</li> <li> XStream: allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream (CVE-2021-21351)</li> <li> netty: Request smuggling via content-length header (CVE-2021-21409)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Red Hat Data Grid is a distributed, in-memory data store.This release of Red Hat Data Grid 8.1.1 serves as a replacement for Red Hat Data Grid 8.1.0, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.Security Fix(es): wildfly-openssl: memory leak per HTTP session creation in WildFly OpenSSL (CVE-2020-25644) XStream: remote code execution due to insecure XML deserialization when relying on blocklists (CVE-2020-26217) infinispan: authorization check missing for server management operations (CVE-2020-25711) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.
Red Hat Data Grid is a distributed, in-memory, NoSQL datastore based on the Infinispan project.This release of Red Hat Data Grid 7.3.8 serves as a replacement for Red Hat Data Grid 7.3.7 and includes bug fixes and enhancements, which are described in the Release Notes, linked to in the References section of this erratum.Security Fix(es): wildfly-openssl: memory leak per HTTP session creation in WildFly OpenSSL (CVE-2020-25644) jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE) (CVE-2020-25649) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.
Red Hat Data Grid is a distributed, in-memory, NoSQL datastore based on the Infinispan project.<br>This release of Red Hat Data Grid 7.3.5 serves as a replacement for Red Hat Data Grid 7.3.4 and includes bug fixes and enhancements, which are described in the Release Notes, linked to in the References section of this erratum.<br>Security Fix(es):<br><li> undertow: possible Denial Of Service (DOS) in Undertow HTTP server listening on HTTPS (CVE-2019-14888)</li> <li> js-jquery: Cross-site scripting via cross-domain ajax requests (CVE-2015-9251)</li> <li> jackson-databind: Serialization gadgets in classes of the commons-configuration package (CVE-2019-14892)</li> <li> jackson-databind: Serialization gadgets in classes of the xalan package (CVE-2019-14893)</li> <li> jackson-databind: polymorphic typing issue related to com.zaxxer.hikari.HikariDataSource (CVE-2019-16335)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Red Hat Data Grid is a distributed, in-memory, NoSQL datastore based on the Infinispan project.<br>This release of Red Hat Data Grid 7.3.3 serves as a replacement for Red Hat Data Grid 7.3.2 and includes bug fixes and enhancements, which are described in the Release Notes, linked to in the References section of this erratum.<br>Security Fix(es):<br><li> HTTP/2: flood using PING frames results in unbounded memory growth (CVE-2019-9512)</li> <li> HTTP/2: flood using HEADERS frames results in unbounded memory growth (CVE-2019-9514)</li> <li> HTTP/2: flood using SETTINGS frames results in unbounded memory growth (CVE-2019-9515)</li> <li> HTTP/2: flood using empty frames results in excessive resource consumption (CVE-2019-9518)</li> <li> xstream: remote code execution due to insecure XML deserialization (regression of CVE-2013-7285) (CVE-2019-10173)</li> <li> infinispan: invokeAccessibly method from ReflectionUtil class allows to invoke private methods (CVE-2019-10174)</li> <li> jackson-databind: default typing mishandling leading to remote code execution (CVE-2019-14379)</li> <li> h2: Information Exposure due to insecure handling of permissions in the backup (CVE-2018-14335)</li> <li> wildfly: Race condition on PID file allows for termination of arbitrary processes by local users (CVE-2019-3805)</li> <li> undertow: leak credentials to log files UndertowLogger.REQUESTLOGGER.undertowRequestFailed (CVE-2019-3888)</li> <li> undertow: DEBUG log for io.undertow.request.security if enabled leaks credentials to log files (CVE-2019-10212)</li> <li> undertow: Information leak in requests for directories without trailing slashes (CVE-2019-10184)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Red Hat Data Grid is a distributed, in-memory, NoSQL datastore based on the Infinispan project.<br>This release of Red Hat Data Grid 7.3.4 serves as a replacement for Red Hat Data Grid 7.3.3 and includes bug fixes and enhancements, which are described in the Release Notes, linked to in the References section of this erratum.<br>Security Fix(es):<br><li> wildfly-core: Incorrect privileges for 'Monitor', 'Auditor' and 'Deployer' user by default (CVE-2019-14838)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Red Hat Data Grid is a distributed, in-memory, NoSQL datastore based on the Infinispan project.<br>This release of Red Hat Data Grid 7.3.2 serves as a replacement for Red Hat Data Grid 7.3.1 and includes bug fixes and enhancements, which are described in the Release Notes, linked to in the References section of this erratum.<br>Security Fix(es):<br><li> infinispan: Session fixation protection broken for Spring Session integration (CVE-2019-10158)</li> <li> jackson-databind: Potential information exfiltration with default typing, serialization gadget from MyBatis (CVE-2018-11307)</li> <li> jackson-databind: improper polymorphic deserialization of types from Jodd-db library (CVE-2018-12022)</li> <li> jackson-databind: improper polymorphic deserialization of types from Oracle JDBC driver (CVE-2018-12023)</li> <li> jackson-databind: arbitrary code execution in slf4j-ext class (CVE-2018-14718)</li> <li> jackson-databind: arbitrary code execution in blaze-ds-opt and blaze-ds-core classes (CVE-2018-14719)</li> <li> jackson-databind: exfiltration/XXE in some JDK classes (CVE-2018-14720)</li> <li> jackson-databind: server-side request forgery (SSRF) in axis2-jaxws class (CVE-2018-14721)</li> <li> jackson-databind: improper polymorphic deserialization in axis2-transport-jms class (CVE-2018-19360)</li> <li> jackson-databind: improper polymorphic deserialization in openjpa class (CVE-2018-19361)</li> <li> jackson-databind: improper polymorphic deserialization in jboss-common-core class (CVE-2018-19362)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Red Hat JBoss Data Grid is a distributed in-memory data grid based on Infinispan.This release of Red Hat JBoss Data Grid 7.2.1 serves as a replacement for Red Hat JBoss Data Grid 7.2.0 and includes bug fixes and enhancements. You can find a link to the Release Notes that describe these bug fixes and enhancements in the References section of this erratum.Security Fix(es): infinispan: deserialization of data in XML and JSON transcoders (CVE-2018-1131) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Red Hat JBoss Data Grid is a distributed in-memory data grid, based on Infinispan.<br>This release of Red Hat JBoss Data Grid 7.2.0 serves as a replacement for Red Hat JBoss Data Grid 7.1.2, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.<br>Security Fix(es):<br><li> slf4j: Deserialisation vulnerability in EventData constructor can allow for arbitrary code execution (CVE-2018-8088)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.<br>Red Hat would like to thank Chris McCown for reporting this issue.
Red Hat JBoss Data Grid is a distributed in-memory data grid, based on Infinispan.<br>This release of Red Hat JBoss Data Grid 7.1.1 serves as a replacement for Red Hat JBoss Data Grid 7.1.0, and includes bug fixes and enhancements, which are documented in the Release Notes linked to in the References.<br>Security Fix(es):<br><li> It was found that Apache Lucene would accept an object from an unauthenticated user that could be manipulated through subsequent post requests. An attacker could use this flaw to assemble an object that could permit execution of arbitrary code if the server enabled Apache Solr's Config API. (CVE-2017-12629)</li> <li> It was found that when using remote logging with log4j socket server the log4j server would deserialize any log event received via TCP or UDP. An attacker could use this flaw to send a specially crafted log event that, during deserialization, would execute arbitrary code in the context of the logger application. (CVE-2017-5645)</li> <li> The hotrod java client in infinispan automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks. (CVE-2016-0750)</li> For more information regarding CVE-2017-12629, see the article linked in the references section.<br>Red Hat would like to thank Sebastian Olsson (TrueSec) for reporting CVE-2016-0750.
Red Hat JBoss Middleware for OpenShift provides images for many of the Red Hat Middleware products, for use with OpenShift Container Platform, with on-premise or private cloud deployments.This errata updates the following images by applying a fix for CVE-2017-5645 (https://access.redhat.com/security/cve/CVE-2017-5645): Red Hat JBoss Enterprise Application Platform 6.4, Red Hat JBoss Enterprise Application Platform 7.0, Red Hat JBoss Web Server 3.0, Red Hat JBoss Web Server 3.1, Red Hat JBoss Data Grid 6.5, Red Hat JBoss BPM Suite 6.3 Process Server, Red Hat JBoss BPM Suite 6.4 Process Server, Red Hat JBoss BRMS 6.3 Decision Server, Red Hat JBoss BRMS 6.4 Decision Server, and Red Hat Single Sign-On 7.0.
Red Hat JBoss Data Grid is a distributed in-memory data grid, based on Infinispan.This release of Red Hat JBoss Data Grid 7.1.0 serves as a replacement for Red Hat JBoss Data Grid 7.0.0, and includes bug fixes and enhancements, which are documented in the Release Notes linked to in the References.Security Fix(es): An infinite-loop vulnerability was discovered in Netty's OpenSslEngine handling of renegotiation. An attacker could exploit this flaw to cause a denial of service. Note: Netty is only vulnerable if renegotiation is enabled (default setting). (CVE-2016-4970) It was found that the REST API in infinispan did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name. (CVE-2017-2638) The CVE-2017-2638 issue was discovered by Jonathan Mason (Red Hat).
Red Hat JBoss Data Grid is a distributed in-memory data grid, based onInfinispan.This asynchronous patch is a security update for JGroups package in Red Hat JBoss Data Grid 6.6. More information about this vulnerability is available at: https://access.redhat.com/articles/2360521 Security Fix(es): It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks. (CVE-2016-2141) The CVE-2016-2141 issue was discovered by Dennis Reed (Red Hat).