{"id":34186,"date":"2022-11-29T19:19:41","date_gmt":"2022-11-29T16:19:41","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/170042\/RHSA-2022-8652-01.txt"},"modified":"2022-11-30T08:40:59","modified_gmt":"2022-11-30T05:10:59","slug":"red-hat-security-advisory-2022-8652-01","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/red-hat-security-advisory-2022-8652-01\/","title":{"rendered":"Red Hat Security Advisory 2022-8652-01"},"content":{"rendered":"<p style=\"text-align: left;\">&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>\nHash: SHA256<\/p>\n<p style=\"text-align: left;\">====================================================================<br \/>\nRed Hat Security Advisory<\/p>\n<p style=\"text-align: left;\">Synopsis: Important: Red Hat Fuse 7.11.1 release and security update<br \/>\nAdvisory ID: RHSA-2022:8652-01<br \/>\nProduct: Red Hat JBoss Fuse<br \/>\nAdvisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:8652<br \/>\nIssue date: 2022-11-28<br \/>\nCVE Names: CVE-2019-8331 CVE-2021-3717 CVE-2021-31684<br \/>\nCVE-2021-44906 CVE-2022-0613 CVE-2022-2048<br \/>\nCVE-2022-2053 CVE-2022-24723 CVE-2022-24785<br \/>\nCVE-2022-24823 CVE-2022-25857 CVE-2022-31129<br \/>\nCVE-2022-31197 CVE-2022-33980 CVE-2022-38749<br \/>\nCVE-2022-41853 CVE-2022-42889<br \/>\n====================================================================<br \/>\n1. Summary:<\/p>\n<p style=\"text-align: left;\">A minor version update (from 7.11 to 7.11.1) is now available for Red Hat<br \/>\nFuse. The purpose of this text-only errata is to inform you about the<br \/>\nsecurity issues fixed in this release.<\/p>\n<p style=\"text-align: left;\">Red Hat Product Security has rated this update as having a security impact<br \/>\nof Important. A Common Vulnerability Scoring System (CVSS) base score,<br \/>\nwhich gives a detailed severity rating, is available for each vulnerability<br \/>\nfrom the CVE link(s) in the References section.<\/p>\n<p style=\"text-align: left;\">2. Description:<\/p>\n<p style=\"text-align: left;\">This release of Red Hat Fuse 7.11.1 serves as a replacement for Red Hat<br \/>\nFuse 7.11 and includes bug fixes and enhancements, which are documented in<br \/>\nthe Release Notes document linked in the References.<\/p>\n<p style=\"text-align: left;\">Security Fix(es):<\/p>\n<p style=\"text-align: left;\">* hsqldb: Untrusted input may lead to RCE attack [fuse-7] (CVE-2022-41853)<\/p>\n<p style=\"text-align: left;\">* io.hawt-hawtio-online: bootstrap: XSS in the tooltip or popover<br \/>\ndata-template attribute [fuse-7] (CVE-2019-8331)<\/p>\n<p style=\"text-align: left;\">* io.hawt-project: bootstrap: XSS in the tooltip or popover data-template<br \/>\nattribute [fuse-7] (CVE-2019-8331)<\/p>\n<p style=\"text-align: left;\">* wildfly: incorrect JBOSS_LOCAL_USER challenge location may lead to giving<br \/>\naccess to all the local users [fuse-7] (CVE-2021-3717)<\/p>\n<p style=\"text-align: left;\">* json-smart: Denial of Service in JSONParserByteArray function [fuse-7]\n(CVE-2021-31684)<\/p>\n<p style=\"text-align: left;\">* io.hawt-hawtio-integration: minimist: prototype pollution [fuse-7]\n(CVE-2021-44906)<\/p>\n<p style=\"text-align: left;\">* urijs: Authorization Bypass Through User-Controlled Key [fuse-7]\n(CVE-2022-0613)<\/p>\n<p style=\"text-align: left;\">* http2-server: Invalid HTTP\/2 requests cause DoS [fuse-7] (CVE-2022-2048)<\/p>\n<p style=\"text-align: left;\">* snakeyaml: Denial of Service due to missing nested depth limitation for<br \/>\ncollections [fuse-7] (CVE-2022-25857)<\/p>\n<p style=\"text-align: left;\">* urijs: Leading white space bypasses protocol validation [fuse-7]\n(CVE-2022-24723)<\/p>\n<p style=\"text-align: left;\">* Moment.js: Path traversal in moment.locale [fuse-7] (CVE-2022-24785)<\/p>\n<p style=\"text-align: left;\">* netty: world readable temporary file containing sensitive data [fuse-7]\n(CVE-2022-24823)<\/p>\n<p style=\"text-align: left;\">* jdbc-postgresql: postgresql: SQL Injection in ResultSet.refreshRow() with<br \/>\nmalicious column names [fuse-7] (CVE-2022-31197)<\/p>\n<p style=\"text-align: left;\">* commons-configuration2: apache-commons-configuration: Apache Commons<br \/>\nConfiguration insecure interpolation defaults [fuse-7] (CVE-2022-33980)<\/p>\n<p style=\"text-align: left;\">* commons-text: apache-commons-text: variable interpolation RCE [fuse-7]\n(CVE-2022-42889)<\/p>\n<p style=\"text-align: left;\">* undertow: Large AJP request may cause DoS [fuse-7] (CVE-2022-2053)<\/p>\n<p style=\"text-align: left;\">* moment: inefficient parsing algorithm resulting in DoS [fuse-7]\n(CVE-2022-31129)<\/p>\n<p style=\"text-align: left;\">* snakeyaml: Uncaught exception in<br \/>\norg.yaml.snakeyaml.composer.Composer.composeSequenceNode [fuse-7]\n(CVE-2022-38749)<\/p>\n<p style=\"text-align: left;\">For more details about the security issues, including the impact, CVSS<br \/>\nscore, acknowledgments, and other related information, refer to the CVE<br \/>\npage(s) listed in the References section.<\/p>\n<p style=\"text-align: left;\">3. Solution:<\/p>\n<p style=\"text-align: left;\">Before applying the update, back up your existing installation, including<br \/>\nall applications, configuration files, databases and database settings, and<br \/>\nso on.<\/p>\n<p style=\"text-align: left;\">Installation instructions are available from the Fuse 7.11.1 product<br \/>\ndocumentation page:<br \/>\nhttps:\/\/access.redhat.com\/documentation\/en-us\/red_hat_fuse\/7.11\/<\/p>\n<p style=\"text-align: left;\">4. Bugs fixed (https:\/\/bugzilla.redhat.com\/):<\/p>\n<p style=\"text-align: left;\">1686454 &#8211; CVE-2019-8331 bootstrap: XSS in the tooltip or popover data-template attribute<br \/>\n1991305 &#8211; CVE-2021-3717 wildfly: incorrect JBOSS_LOCAL_USER challenge location may lead to giving access to all the local users<br \/>\n2055496 &#8211; CVE-2022-0613 urijs: Authorization Bypass Through User-Controlled Key<br \/>\n2062370 &#8211; CVE-2022-24723 urijs: Leading white space bypasses protocol validation<br \/>\n2066009 &#8211; CVE-2021-44906 minimist: prototype pollution<br \/>\n2072009 &#8211; CVE-2022-24785 Moment.js: Path traversal in moment.locale<br \/>\n2087186 &#8211; CVE-2022-24823 netty: world readable temporary file containing sensitive data<br \/>\n2095862 &#8211; CVE-2022-2053 undertow: Large AJP request may cause DoS<br \/>\n2102695 &#8211; CVE-2021-31684 json-smart: Denial of Service in JSONParserByteArray function<br \/>\n2105067 &#8211; CVE-2022-33980 apache-commons-configuration: Apache Commons Configuration insecure interpolation defaults<br \/>\n2105075 &#8211; CVE-2022-31129 moment: inefficient parsing algorithm resulting in DoS<br \/>\n2116952 &#8211; CVE-2022-2048 http2-server: Invalid HTTP\/2 requests cause DoS<br \/>\n2126789 &#8211; CVE-2022-25857 snakeyaml: Denial of Service due to missing nested depth limitation for collections<br \/>\n2129428 &#8211; CVE-2022-31197 postgresql: SQL Injection in ResultSet.refreshRow() with malicious column names<br \/>\n2129706 &#8211; CVE-2022-38749 snakeyaml: Uncaught exception in org.yaml.snakeyaml.composer.Composer.composeSequenceNode<br \/>\n2135435 &#8211; CVE-2022-42889 apache-commons-text: variable interpolation RCE<br \/>\n2136141 &#8211; CVE-2022-41853 hsqldb: Untrusted input may lead to RCE attack<\/p>\n<p style=\"text-align: left;\">5. References:<\/p>\n<p style=\"text-align: left;\">https:\/\/access.redhat.com\/security\/cve\/CVE-2019-8331<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3717<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-31684<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-44906<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0613<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-2048<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-2053<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-24723<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-24785<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-24823<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-25857<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-31129<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-31197<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-33980<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-38749<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-41853<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-42889<br \/>\nhttps:\/\/access.redhat.com\/security\/updates\/classification\/#important<\/p>\n<p style=\"text-align: left;\">6. Contact:<\/p>\n<p style=\"text-align: left;\">The Red Hat security contact is &lt;secalert@redhat.com&gt;. More contact<br \/>\ndetails at https:\/\/access.redhat.com\/security\/team\/contact\/<\/p>\n<p style=\"text-align: left;\">Copyright 2022 Red Hat, Inc.<br \/>\n&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<br \/>\nVersion: GnuPG v1<\/p>\n<p style=\"text-align: left;\">iQIVAwUBY4UEJdzjgjWX9erEAQg9jw\/\/bHEzcxXGN9kNp1msJRaz6iQEu7dv9TYV<br \/>\nN1lsrfJEc\/fosdjIilTzia9hKhMVvbC6iv6lWGc6s3E9t48vGdSYLHbh+qHnFo7t<br \/>\nWtrjZnejl53WYwRc70oyeUmXTNrrd9iuATkvkFF6MA024hcJFksuiHmF5\/Awa9T8<br \/>\nsSsLbm5eutvBz1rBDGgcq4fDCFB40YmKsLKhzHrV0SpeZKTCgwNyzvpAVVlsxXhk<br \/>\nOSSCmda+ZTxkA9+gaTsJqqeBeDgHhSL+PVzWOYuRM6wT49tkwSJHfBs9EgV55IjE<br \/>\nIVOQm3oGUyMSGBjbbiD8NuYEQkAip8AK0eTIQbaWW4n9geXpw5VOh\/E3U8u+a9xY<br \/>\nh0pAs6ACta+fD3d9hSabTkDDno6NU94bcmKh2rfpNvj6h9UX0Ca0lKMZ25t6zUln<br \/>\n2OHzLhilUnbOSwnE709NBaEaI4t\/aev1TBpeZ1KFpn\/6Mdbx6pvjuh76kCHwdg7o<br \/>\nOVsrvplG6hJ93S5vNNYxwfcL7TFNyWBcHR0Em7D51zZ87HkzYcNh9Ay481BgXGz+<br \/>\nz2N71zc+h0auaMo5bnL68hMSjFmhiMWZmfy1H8w2Sz6fol8iO\/aYI\/ddv\/8aYP1k<br \/>\n3ZMY7ygpkvcryPaz7VKixbX7yZNOI2gfXl2zDSvIoOjaajND4ctdidxJ9MeZYj6r<br \/>\nWzRyyCDzfVo=IsTh<br \/>\n&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<br \/>\n&#8212;<br \/>\nRHSA-announce mailing list<br \/>\nRHSA-announce@redhat.com<br \/>\nhttps:\/\/listman.redhat.com\/mailman\/listinfo\/rhsa-announce<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211; Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Fuse 7.11.1 release and security update Advisory ID: RHSA-2022:8652-01 Product: Red Hat JBoss Fuse Advisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:8652 Issue date: 2022-11-28 CVE Names: CVE-2019-8331 CVE-2021-3717 CVE-2021-31684 CVE-2021-44906 CVE-2022-0613 CVE-2022-2048 CVE-2022-2053 CVE-2022-24723 CVE-2022-24785 CVE-2022-24823 CVE-2022-25857 CVE-2022-31129 CVE-2022-31197 CVE-2022-33980 CVE-2022-38749 CVE-2022-41853 CVE-2022-42889 ==================================================================== &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-34186","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34186","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=34186"}],"version-history":[{"count":1,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34186\/revisions"}],"predecessor-version":[{"id":34200,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34186\/revisions\/34200"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=34186"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=34186"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=34186"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}