ID

VAR-201908-0421


CVE

CVE-2019-9511


TITLE

HTTP/2 implementations do not robustly handle abnormal traffic and resource exhaustion

Trust: 0.8

sources: CERT/CC: VU#605641

DESCRIPTION

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both. Multiple HTTP/2 implementations are vulnerable to a variety of denial-of-service (DoS) attacks. HTTP/2 is the second version of the hypertext transfer protocol, which is mainly used to ensure the communication between the client and the server. A resource management error vulnerability exists in HTTP/2. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 Security Release on RHEL 6 Advisory ID: RHSA-2019:3932-01 Product: Red Hat JBoss Core Services Advisory URL: https://access.redhat.com/errata/RHSA-2019:3932 Issue date: 2019-11-20 CVE Names: CVE-2018-0734 CVE-2018-0737 CVE-2018-5407 CVE-2018-17189 CVE-2018-17199 CVE-2019-0196 CVE-2019-0197 CVE-2019-0217 CVE-2019-9511 CVE-2019-9513 CVE-2019-9516 CVE-2019-9517 ===================================================================== 1. Summary: Updated packages that provide Red Hat JBoss Core Services Pack Apache Server 2.4.37 and fix several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat JBoss Core Services on RHEL 6 Server - i386, noarch, ppc64, x86_64 3. Description: This release adds the new Apache HTTP Server 2.4.37 packages that are part of the JBoss Core Services offering. This release serves as a replacement for Red Hat JBoss Core Services Pack Apache Server 2.4.29 and includes bug fixes and enhancements. Refer to the Release Notes for information on the most significant bug fixes and enhancements included in this release. Security Fix(es): * openssl: RSA key generation cache timing vulnerability in crypto/rsa/rsa_gen.c allows attackers to recover private keys (CVE-2018-0737) * openssl: timing side channel attack in the DSA signature algorithm (CVE-2018-0734) * mod_auth_digest: access control bypass due to race condition (CVE-2019-0217) * openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) (CVE-2018-5407) * mod_session_cookie does not respect expiry time (CVE-2018-17199) * mod_http2: DoS via slow, unneeded request bodies (CVE-2018-17189) * mod_http2: possible crash on late upgrade (CVE-2019-0197) * mod_http2: read-after-free on a string compare (CVE-2019-0196) * nghttp2: HTTP/2: large amount of data request leads to denial of service (CVE-2019-9511) * nghttp2: HTTP/2: flood using PRIORITY frames resulting in excessive resource consumption (CVE-2019-9513) * mod_http2: HTTP/2: 0-length headers leads to denial of service (CVE-2019-9516) * mod_http2: HTTP/2: request for large response leads to denial of service (CVE-2019-9517) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 For the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted. After installing the updated packages, the httpd daemon will be restarted automatically. 5. Bugs fixed (https://bugzilla.redhat.com/): 1568253 - CVE-2018-0737 openssl: RSA key generation cache timing vulnerability in crypto/rsa/rsa_gen.c allows attackers to recover private keys 1644364 - CVE-2018-0734 openssl: timing side channel attack in the DSA signature algorithm 1645695 - CVE-2018-5407 openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) 1668493 - CVE-2018-17199 httpd: mod_session_cookie does not respect expiry time 1668497 - CVE-2018-17189 httpd: mod_http2: DoS via slow, unneeded request bodies 1695020 - CVE-2019-0217 httpd: mod_auth_digest: access control bypass due to race condition 1695030 - CVE-2019-0196 httpd: mod_http2: read-after-free on a string compare 1695042 - CVE-2019-0197 httpd: mod_http2: possible crash on late upgrade 1735741 - CVE-2019-9513 HTTP/2: flood using PRIORITY frames results in excessive resource consumption 1741860 - CVE-2019-9511 HTTP/2: large amount of data requests leads to denial of service 1741864 - CVE-2019-9516 HTTP/2: 0-length headers lead to denial of service 1741868 - CVE-2019-9517 HTTP/2: request for large response leads to denial of service 6. Package List: Red Hat JBoss Core Services on RHEL 6 Server: Source: jbcs-httpd24-apr-1.6.3-63.jbcs.el6.src.rpm jbcs-httpd24-apr-util-1.6.1-48.jbcs.el6.src.rpm jbcs-httpd24-brotli-1.0.6-7.jbcs.el6.src.rpm jbcs-httpd24-curl-7.64.1-14.jbcs.el6.src.rpm jbcs-httpd24-httpd-2.4.37-33.jbcs.el6.src.rpm jbcs-httpd24-jansson-2.11-20.jbcs.el6.src.rpm jbcs-httpd24-mod_cluster-native-1.3.12-9.Final_redhat_2.jbcs.el6.src.rpm jbcs-httpd24-mod_jk-1.2.46-22.redhat_1.jbcs.el6.src.rpm jbcs-httpd24-mod_security-2.9.2-16.GA.jbcs.el6.src.rpm jbcs-httpd24-nghttp2-1.39.2-4.jbcs.el6.src.rpm jbcs-httpd24-openssl-1.1.1-25.jbcs.el6.src.rpm i386: jbcs-httpd24-apr-1.6.3-63.jbcs.el6.i686.rpm jbcs-httpd24-apr-debuginfo-1.6.3-63.jbcs.el6.i686.rpm jbcs-httpd24-apr-devel-1.6.3-63.jbcs.el6.i686.rpm jbcs-httpd24-apr-util-1.6.1-48.jbcs.el6.i686.rpm jbcs-httpd24-apr-util-debuginfo-1.6.1-48.jbcs.el6.i686.rpm jbcs-httpd24-apr-util-devel-1.6.1-48.jbcs.el6.i686.rpm jbcs-httpd24-apr-util-ldap-1.6.1-48.jbcs.el6.i686.rpm jbcs-httpd24-apr-util-mysql-1.6.1-48.jbcs.el6.i686.rpm jbcs-httpd24-apr-util-nss-1.6.1-48.jbcs.el6.i686.rpm jbcs-httpd24-apr-util-odbc-1.6.1-48.jbcs.el6.i686.rpm jbcs-httpd24-apr-util-openssl-1.6.1-48.jbcs.el6.i686.rpm jbcs-httpd24-apr-util-pgsql-1.6.1-48.jbcs.el6.i686.rpm jbcs-httpd24-apr-util-sqlite-1.6.1-48.jbcs.el6.i686.rpm jbcs-httpd24-brotli-1.0.6-7.jbcs.el6.i686.rpm jbcs-httpd24-brotli-debuginfo-1.0.6-7.jbcs.el6.i686.rpm jbcs-httpd24-brotli-devel-1.0.6-7.jbcs.el6.i686.rpm jbcs-httpd24-curl-7.64.1-14.jbcs.el6.i686.rpm jbcs-httpd24-curl-debuginfo-7.64.1-14.jbcs.el6.i686.rpm jbcs-httpd24-httpd-2.4.37-33.jbcs.el6.i686.rpm jbcs-httpd24-httpd-debuginfo-2.4.37-33.jbcs.el6.i686.rpm jbcs-httpd24-httpd-devel-2.4.37-33.jbcs.el6.i686.rpm jbcs-httpd24-httpd-selinux-2.4.37-33.jbcs.el6.i686.rpm jbcs-httpd24-httpd-tools-2.4.37-33.jbcs.el6.i686.rpm jbcs-httpd24-jansson-2.11-20.jbcs.el6.i686.rpm jbcs-httpd24-jansson-debuginfo-2.11-20.jbcs.el6.i686.rpm jbcs-httpd24-jansson-devel-2.11-20.jbcs.el6.i686.rpm jbcs-httpd24-libcurl-7.64.1-14.jbcs.el6.i686.rpm jbcs-httpd24-libcurl-devel-7.64.1-14.jbcs.el6.i686.rpm jbcs-httpd24-mod_cluster-native-1.3.12-9.Final_redhat_2.jbcs.el6.i686.rpm jbcs-httpd24-mod_cluster-native-debuginfo-1.3.12-9.Final_redhat_2.jbcs.el6.i686.rpm jbcs-httpd24-mod_jk-ap24-1.2.46-22.redhat_1.jbcs.el6.i686.rpm jbcs-httpd24-mod_jk-debuginfo-1.2.46-22.redhat_1.jbcs.el6.i686.rpm jbcs-httpd24-mod_jk-manual-1.2.46-22.redhat_1.jbcs.el6.i686.rpm jbcs-httpd24-mod_ldap-2.4.37-33.jbcs.el6.i686.rpm jbcs-httpd24-mod_md-2.4.37-33.jbcs.el6.i686.rpm jbcs-httpd24-mod_proxy_html-2.4.37-33.jbcs.el6.i686.rpm jbcs-httpd24-mod_security-2.9.2-16.GA.jbcs.el6.i686.rpm jbcs-httpd24-mod_security-debuginfo-2.9.2-16.GA.jbcs.el6.i686.rpm jbcs-httpd24-mod_session-2.4.37-33.jbcs.el6.i686.rpm jbcs-httpd24-mod_ssl-2.4.37-33.jbcs.el6.i686.rpm jbcs-httpd24-nghttp2-1.39.2-4.jbcs.el6.i686.rpm jbcs-httpd24-nghttp2-debuginfo-1.39.2-4.jbcs.el6.i686.rpm jbcs-httpd24-nghttp2-devel-1.39.2-4.jbcs.el6.i686.rpm jbcs-httpd24-openssl-1.1.1-25.jbcs.el6.i686.rpm jbcs-httpd24-openssl-debuginfo-1.1.1-25.jbcs.el6.i686.rpm jbcs-httpd24-openssl-devel-1.1.1-25.jbcs.el6.i686.rpm jbcs-httpd24-openssl-libs-1.1.1-25.jbcs.el6.i686.rpm jbcs-httpd24-openssl-perl-1.1.1-25.jbcs.el6.i686.rpm jbcs-httpd24-openssl-static-1.1.1-25.jbcs.el6.i686.rpm noarch: jbcs-httpd24-httpd-manual-2.4.37-33.jbcs.el6.noarch.rpm ppc64: jbcs-httpd24-brotli-1.0.6-7.jbcs.el6.ppc64.rpm jbcs-httpd24-brotli-debuginfo-1.0.6-7.jbcs.el6.ppc64.rpm jbcs-httpd24-brotli-devel-1.0.6-7.jbcs.el6.ppc64.rpm jbcs-httpd24-curl-7.64.1-14.jbcs.el6.ppc64.rpm jbcs-httpd24-curl-debuginfo-7.64.1-14.jbcs.el6.ppc64.rpm jbcs-httpd24-httpd-debuginfo-2.4.37-33.jbcs.el6.ppc64.rpm jbcs-httpd24-jansson-2.11-20.jbcs.el6.ppc64.rpm jbcs-httpd24-jansson-debuginfo-2.11-20.jbcs.el6.ppc64.rpm jbcs-httpd24-jansson-devel-2.11-20.jbcs.el6.ppc64.rpm jbcs-httpd24-libcurl-7.64.1-14.jbcs.el6.ppc64.rpm jbcs-httpd24-libcurl-devel-7.64.1-14.jbcs.el6.ppc64.rpm jbcs-httpd24-mod_md-2.4.37-33.jbcs.el6.ppc64.rpm x86_64: jbcs-httpd24-apr-1.6.3-63.jbcs.el6.x86_64.rpm jbcs-httpd24-apr-debuginfo-1.6.3-63.jbcs.el6.x86_64.rpm jbcs-httpd24-apr-devel-1.6.3-63.jbcs.el6.x86_64.rpm jbcs-httpd24-apr-util-1.6.1-48.jbcs.el6.x86_64.rpm jbcs-httpd24-apr-util-debuginfo-1.6.1-48.jbcs.el6.x86_64.rpm jbcs-httpd24-apr-util-devel-1.6.1-48.jbcs.el6.x86_64.rpm jbcs-httpd24-apr-util-ldap-1.6.1-48.jbcs.el6.x86_64.rpm jbcs-httpd24-apr-util-mysql-1.6.1-48.jbcs.el6.x86_64.rpm jbcs-httpd24-apr-util-nss-1.6.1-48.jbcs.el6.x86_64.rpm jbcs-httpd24-apr-util-odbc-1.6.1-48.jbcs.el6.x86_64.rpm jbcs-httpd24-apr-util-openssl-1.6.1-48.jbcs.el6.x86_64.rpm jbcs-httpd24-apr-util-pgsql-1.6.1-48.jbcs.el6.x86_64.rpm jbcs-httpd24-apr-util-sqlite-1.6.1-48.jbcs.el6.x86_64.rpm jbcs-httpd24-brotli-1.0.6-7.jbcs.el6.x86_64.rpm jbcs-httpd24-brotli-debuginfo-1.0.6-7.jbcs.el6.x86_64.rpm jbcs-httpd24-brotli-devel-1.0.6-7.jbcs.el6.x86_64.rpm jbcs-httpd24-curl-7.64.1-14.jbcs.el6.x86_64.rpm jbcs-httpd24-curl-debuginfo-7.64.1-14.jbcs.el6.x86_64.rpm jbcs-httpd24-httpd-2.4.37-33.jbcs.el6.x86_64.rpm jbcs-httpd24-httpd-debuginfo-2.4.37-33.jbcs.el6.x86_64.rpm jbcs-httpd24-httpd-devel-2.4.37-33.jbcs.el6.x86_64.rpm jbcs-httpd24-httpd-selinux-2.4.37-33.jbcs.el6.x86_64.rpm jbcs-httpd24-httpd-tools-2.4.37-33.jbcs.el6.x86_64.rpm jbcs-httpd24-jansson-2.11-20.jbcs.el6.x86_64.rpm jbcs-httpd24-jansson-debuginfo-2.11-20.jbcs.el6.x86_64.rpm jbcs-httpd24-jansson-devel-2.11-20.jbcs.el6.x86_64.rpm jbcs-httpd24-libcurl-7.64.1-14.jbcs.el6.x86_64.rpm jbcs-httpd24-libcurl-devel-7.64.1-14.jbcs.el6.x86_64.rpm jbcs-httpd24-mod_cluster-native-1.3.12-9.Final_redhat_2.jbcs.el6.x86_64.rpm jbcs-httpd24-mod_cluster-native-debuginfo-1.3.12-9.Final_redhat_2.jbcs.el6.x86_64.rpm jbcs-httpd24-mod_jk-ap24-1.2.46-22.redhat_1.jbcs.el6.x86_64.rpm jbcs-httpd24-mod_jk-debuginfo-1.2.46-22.redhat_1.jbcs.el6.x86_64.rpm jbcs-httpd24-mod_jk-manual-1.2.46-22.redhat_1.jbcs.el6.x86_64.rpm jbcs-httpd24-mod_ldap-2.4.37-33.jbcs.el6.x86_64.rpm jbcs-httpd24-mod_md-2.4.37-33.jbcs.el6.x86_64.rpm jbcs-httpd24-mod_proxy_html-2.4.37-33.jbcs.el6.x86_64.rpm jbcs-httpd24-mod_security-2.9.2-16.GA.jbcs.el6.x86_64.rpm jbcs-httpd24-mod_security-debuginfo-2.9.2-16.GA.jbcs.el6.x86_64.rpm jbcs-httpd24-mod_session-2.4.37-33.jbcs.el6.x86_64.rpm jbcs-httpd24-mod_ssl-2.4.37-33.jbcs.el6.x86_64.rpm jbcs-httpd24-nghttp2-1.39.2-4.jbcs.el6.x86_64.rpm jbcs-httpd24-nghttp2-debuginfo-1.39.2-4.jbcs.el6.x86_64.rpm jbcs-httpd24-nghttp2-devel-1.39.2-4.jbcs.el6.x86_64.rpm jbcs-httpd24-openssl-1.1.1-25.jbcs.el6.x86_64.rpm jbcs-httpd24-openssl-debuginfo-1.1.1-25.jbcs.el6.x86_64.rpm jbcs-httpd24-openssl-devel-1.1.1-25.jbcs.el6.x86_64.rpm jbcs-httpd24-openssl-libs-1.1.1-25.jbcs.el6.x86_64.rpm jbcs-httpd24-openssl-perl-1.1.1-25.jbcs.el6.x86_64.rpm jbcs-httpd24-openssl-static-1.1.1-25.jbcs.el6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-0734 https://access.redhat.com/security/cve/CVE-2018-0737 https://access.redhat.com/security/cve/CVE-2018-5407 https://access.redhat.com/security/cve/CVE-2018-17189 https://access.redhat.com/security/cve/CVE-2018-17199 https://access.redhat.com/security/cve/CVE-2019-0196 https://access.redhat.com/security/cve/CVE-2019-0197 https://access.redhat.com/security/cve/CVE-2019-0217 https://access.redhat.com/security/cve/CVE-2019-9511 https://access.redhat.com/security/cve/CVE-2019-9513 https://access.redhat.com/security/cve/CVE-2019-9516 https://access.redhat.com/security/cve/CVE-2019-9517 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXdVoL9zjgjWX9erEAQhDLw/+Mfjt8An133D/dKW5oR9yMg62DEEC/4Cg dZmxKhl19OMZAZuW50cGKv2FpDmJrKdXXD3t5qral22H0PytI9//FOIhWI1iz6Iz dUezvO+lWWaKUQ7KoInxh+GX64/ll+uVfBqOW3I4FWA4ZHw27/kUVHfymD/7GBUQ YsZaaiy8jKHA0VfcjtZva9GJZ4/GkhBZF4xobzgxzKurv4jsvRZaRcf8pV8ty4ll e55/G3YVyLi7nzF5l/EWKLBOhi6EPVWPO7QcjrVyIJ8126UypxPgcVvst85GAFV9 waZVdRpbcMmGqm6yc+1+3Xz9t+uY4Kxa6/fgnTJGsKDhMyscdTzi5p/Ckoeu72u9 xdrvL5z9cQraY9j5O0E5rjc0zaqKXsKIBd4hi33HTO/DhQgCFvJFIZT6oLFsv6Iz mK0fC6v+7BDF01pKdjHRS6p/iEUKP5u5Dnrto/GPUGRS8RMcxLyCCHGttM50swgQ AJaXKchifSn00H2Dg+bb7z3mUZejPBLfDN39rvKzyonQd+GlDZUlprWtPVgu3qlC zQjLuPdbDIHnDPgTK+7MqNEM7DHyI/APh0l33/tjjtBG9ybLgGYDUSafPDA3caZM IIqBDEZ8ztDMVaSrkmQdI6onBFBJBYfQ5zu8VI6zxPQXs6vC0r9KlMAG7KqUihr4 eV0hw7GzzDQ= =xwun -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce . The purpose of this text-only errata is to inform you about the security issues fixed in this release. Installation instructions are available from the Fuse 7.7.0 product documentation page: https://access.redhat.com/documentation/en-us/red_hat_fuse/7.7/ 4. Bugs fixed (https://bugzilla.redhat.com/): 1343616 - CVE-2016-4970 netty: Infinite loop vulnerability when handling renegotiation using SslProvider.OpenSsl 1620529 - CVE-2018-1000632 dom4j: XML Injection in Class: Element. Methods: addElement, addAttribute which can impact the integrity of XML documents 1632452 - CVE-2018-3831 elasticsearch: Information exposure via _cluster/settings API 1637492 - CVE-2018-11797 pdfbox: unbounded computation in parser resulting in a denial of service 1638391 - CVE-2018-12541 vertx: WebSocket HTTP upgrade implementation holds the entire http request in memory before the handshake 1697598 - CVE-2019-3797 spring-data-jpa: Additional information exposure with Spring Data JPA derived queries 1700016 - CVE-2019-0231 mina-core: Retaining an open socket in close_notify SSL-TLS leading to Information disclosure. 1713468 - CVE-2019-12086 jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files on the server. 1715075 - CVE-2019-10172 jackson-mapper-asl: XML external entity similar to CVE-2016-3720 1728604 - CVE-2019-9827 hawtio: server side request forgery via initial /proxy/ substring of a URI 1741860 - CVE-2019-9511 HTTP/2: large amount of data requests leads to denial of service 1752770 - CVE-2020-1757 undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass 1755831 - CVE-2019-16335 jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariDataSource 1755849 - CVE-2019-14540 jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariConfig 1758167 - CVE-2019-17267 jackson-databind: Serialization gadgets in classes of the ehcache package 1758171 - CVE-2019-14892 jackson-databind: Serialization gadgets in classes of the commons-configuration package 1758182 - CVE-2019-14893 jackson-databind: Serialization gadgets in classes of the xalan package 1758187 - CVE-2019-16942 jackson-databind: Serialization gadgets in org.apache.commons.dbcp.datasources.* 1758191 - CVE-2019-16943 jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSource 1764658 - CVE-2019-12400 xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source 1767483 - CVE-2019-10086 apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default 1772464 - CVE-2019-14888 undertow: possible Denial Of Service (DOS) in Undertow HTTP server listening on HTTPS 1775293 - CVE-2019-17531 jackson-databind: Serialization gadgets in org.apache.log4j.receivers.db.* 1793154 - CVE-2019-20330 jackson-databind: lacks certain net.sf.ehcache blocking 1796225 - CVE-2020-7238 netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling 1797011 - CVE-2019-17573 cxf: reflected XSS in the services listing page 1798509 - CVE-2019-20445 netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header 1798524 - CVE-2019-20444 netty: HTTP request smuggling 1807305 - CVE-2020-1745 undertow: AJP File Read/Inclusion Vulnerability 1815212 - CVE-2020-1953 apache-commons-configuration: uncontrolled class instantiation when loading YAML files 1815470 - CVE-2020-10673 jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution 1815495 - CVE-2020-10672 jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution 1816330 - CVE-2020-8840 jackson-databind: Lacks certain xbean-reflect/JNDI blocking 1816332 - CVE-2020-9546 jackson-databind: Serialization gadgets in shaded-hikari-config 1816337 - CVE-2020-9547 jackson-databind: Serialization gadgets in ibatis-sqlmap 1816340 - CVE-2020-9548 jackson-databind: Serialization gadgets in anteros-core 1819208 - CVE-2020-10968 jackson-databind: Serialization gadgets in org.aoju.bus.proxy.provider.*.RmiProvider 1819212 - CVE-2020-10969 jackson-databind: Serialization gadgets in javax.swing.JEditorPane 1821304 - CVE-2020-11111 jackson-databind: Serialization gadgets in org.apache.activemq.jms.pool.XaPooledConnectionFactory 1821311 - CVE-2020-11112 jackson-databind: Serialization gadgets in org.apache.commons.proxy.provider.remoting.RmiProvider 1821315 - CVE-2020-11113 jackson-databind: Serialization gadgets in org.apache.openjpa.ee.WASRegistryManagedRuntime 1826798 - CVE-2020-11620 jackson-databind: Serialization gadgets in commons-jelly:commons-jelly 1826805 - CVE-2020-11619 jackson-databind: Serialization gadgets in org.springframework:spring-aop 1848958 - CVE-2020-14195 jackson-databind: serialization in org.jsecurity.realm.jndi.JndiRealmFactory 1848960 - CVE-2020-14060 jackson-databind: serialization in oadd.org.apache.xalan.lib.sql.JNDIConnectionPool 1848962 - CVE-2020-14062 jackson-databind: serialization in com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool 1848966 - CVE-2020-14061 jackson-databind: serialization in weblogic/oracle-aqjms 5. Description: AMQ Broker is a high-performance messaging implementation based on ActiveMQ Artemis. It uses an asynchronous journal for fast message persistence, and supports multiple languages, protocols, and platforms. The References section of this erratum contains a download link (you must log in to download the update). 8) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: Nginx is a web server and a reverse proxy server for HTTP, SMTP, POP3 (Post Office Protocol 3) and IMAP protocols, with a focus on high concurrency, performance and low memory usage. Description: Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. Solution: Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. Bugs fixed (https://bugzilla.redhat.com/): 1735645 - CVE-2019-9512 HTTP/2: flood using PING frames results in unbounded memory growth 1735744 - CVE-2019-9514 HTTP/2: flood using HEADERS frames results in unbounded memory growth 1735745 - CVE-2019-9515 HTTP/2: flood using SETTINGS frames results in unbounded memory growth 1741860 - CVE-2019-9511 HTTP/2: large amount of data requests leads to denial of service 1751227 - CVE-2019-14838 wildfly-core: Incorrect privileges for 'Monitor', 'Auditor' and 'Deployer' user by default 1752980 - CVE-2019-14843 wildfly-security-manager: security manager authorization bypass 6. JIRA issues fixed (https://issues.jboss.org/): JBEAP-17075 - (7.2.z) Upgrade yasson from 1.0.2.redhat-00001 to 1.0.5 JBEAP-17220 - (7.2.x) HHH-13504 Upgrade ByteBuddy to 1.9.11 JBEAP-17365 - [GSS](7.2.z) Upgrade RESTEasy from 3.6.1.SP6 to 3.6.1.SP7 JBEAP-17476 - [GSS](7.2.z) Upgrade Generic JMS RA 2.0.2.Final JBEAP-17478 - [GSS](7.2.z) Upgrade JBoss Remoting from 5.0.14.SP1 to 5.0.16.Final JBEAP-17483 - [GSS](7.2.z) Upgrade Apache CXF from 3.2.9 to 3.2.10 JBEAP-17495 - (7.2.z) Upgrade PicketLink from 2.5.5.SP12-redhat-00007 to 2.5.5.SP12-redhat-00009 JBEAP-17496 - (7.2.z) Upgrade PicketLink bindings from 2.5.5.SP12-redhat-00007 to 2.5.5.SP12-redhat-00009 JBEAP-17513 - [GSS](7.2.z) Upgrade Hibernate ORM from 5.3.11.SP1 to 5.3.13 JBEAP-17521 - (7.2.z) Upgrade picketbox from 5.0.3.Final-redhat-00004 to 5.0.3.Final-redhat-00005 JBEAP-17523 - [GSS](7.2.z) Upgrade wildfly-core from 6.0.16 to 6.0.17 JBEAP-17547 - [GSS](7.2.z) Upgrade Elytron-Tool from 1.4.3 to 1.4.4.Final JBEAP-17548 - [GSS](7.2.z) Upgrade Elytron from 1.6.4.Final-redhat-00001 to 1.6.5.Final-redhat-00001 JBEAP-17560 - [GSS](7.2.z) Upgrade HAL from 3.0.16 to 3.0.17 JBEAP-17579 - [GSS](7.2.z) Upgrade JBoss MSC from 1.4.8 to 1.4.11 JBEAP-17582 - [GSS](7.2.z) Upgrade JSF based on Mojarra 2.3.5.SP3-redhat-00002 to 2.3.5.SP3-redhat-00003 JBEAP-17603 - Tracker bug for the EAP 7.2.5 release for RHEL-6 JBEAP-17631 - [GSS](7.2.z) Upgrade Undertow from 2.0.25.SP1 to 2.0.26.SP3 JBEAP-17647 - [GSS](7.2.z) Upgrade IronJacamar from 1.4.17.Final to 1.4.18.Final JBEAP-17665 - [GSS](7.2.z) Upgrade XNIO from 3.7.3.Final-redhat-00001 to 3.7.6.Final JBEAP-17722 - [GSS](7.2.z) Upgrade wildfly-http-client from 1.0.15.Final-redhat-00001 to 1.0.17.Final JBEAP-17874 - (7.2.z) Upgrade to wildfly-openssl 1.0.8 JBEAP-17880 - (7.2.z) Upgrade XNIO from 3.7.6.Final-redhat-00001 to 3.7.6.SP1 7. Bug Fix(es): * Fixed repository mirror credentials properly escaped to allow special characters * Fixed repository mirror UI cancel button enabled * Fixed repository mirror UI change next sync date 3. Solution: Please download the release images via: quay.io/redhat/quay:v3.1.1 quay.io/redhat/clair-jwt:v3.1.1 quay.io/redhat/quay-builder:v3.1.1 4. Summary: This is a security update for JBoss EAP Continuous Delivery 18.0. You must restart the JBoss server process for the update to take effect. ========================================================================== Ubuntu Security Notice USN-6754-1 April 25, 2024 nghttp2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in nghttp2. Software Description: - nghttp2: HTTP/2 C Library and tools Details: It was discovered that nghttp2 incorrectly handled the HTTP/2 implementation. A remote attacker could possibly use this issue to cause nghttp2 to consume resources, leading to a denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-9511, CVE-2019-9513) It was discovered that nghttp2 incorrectly handled request cancellation. A remote attacker could possibly use this issue to cause nghttp2 to consume resources, leading to a denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2023-44487) It was discovered that nghttp2 could be made to process an unlimited number of HTTP/2 CONTINUATION frames. A remote attacker could possibly use this issue to cause nghttp2 to consume resources, leading to a denial of service. (CVE-2024-28182) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10: libnghttp2-14 1.55.1-1ubuntu0.2 nghttp2 1.55.1-1ubuntu0.2 nghttp2-client 1.55.1-1ubuntu0.2 nghttp2-proxy 1.55.1-1ubuntu0.2 nghttp2-server 1.55.1-1ubuntu0.2 Ubuntu 22.04 LTS: libnghttp2-14 1.43.0-1ubuntu0.2 nghttp2 1.43.0-1ubuntu0.2 nghttp2-client 1.43.0-1ubuntu0.2 nghttp2-proxy 1.43.0-1ubuntu0.2 nghttp2-server 1.43.0-1ubuntu0.2 Ubuntu 20.04 LTS: libnghttp2-14 1.40.0-1ubuntu0.3 nghttp2 1.40.0-1ubuntu0.3 nghttp2-client 1.40.0-1ubuntu0.3 nghttp2-proxy 1.40.0-1ubuntu0.3 nghttp2-server 1.40.0-1ubuntu0.3 Ubuntu 18.04 LTS (Available with Ubuntu Pro): libnghttp2-14 1.30.0-1ubuntu1+esm2 nghttp2 1.30.0-1ubuntu1+esm2 nghttp2-client 1.30.0-1ubuntu1+esm2 nghttp2-proxy 1.30.0-1ubuntu1+esm2 nghttp2-server 1.30.0-1ubuntu1+esm2 Ubuntu 16.04 LTS (Available with Ubuntu Pro): libnghttp2-14 1.7.1-1ubuntu0.1~esm2 nghttp2 1.7.1-1ubuntu0.1~esm2 nghttp2-client 1.7.1-1ubuntu0.1~esm2 nghttp2-proxy 1.7.1-1ubuntu0.1~esm2 nghttp2-server 1.7.1-1ubuntu0.1~esm2 In general, a standard system update will make all the necessary changes. The following advisory data is extracted from: https://access.redhat.com/security/data/csaf/v2/advisories/2024/rhsa-2024_5856.json Red Hat officially shut down their mailing list notifications October 10, 2023. Due to this, Packet Storm has recreated the below data as a reference point to raise awareness. It must be noted that due to an inability to easily track revision updates without crawling Red Hat's archive, these advisories are single notifications and we strongly suggest that you visit the Red Hat provided links to ensure you have the latest information available if the subject matter listed pertains to your environment

Trust: 2.52

sources: NVD: CVE-2019-9511 // CERT/CC: VU#605641 // VULHUB: VHN-160946 // PACKETSTORM: 155417 // PACKETSTORM: 158636 // PACKETSTORM: 157214 // PACKETSTORM: 154533 // PACKETSTORM: 155483 // PACKETSTORM: 154725 // PACKETSTORM: 158095 // PACKETSTORM: 178284 // PACKETSTORM: 180394

AFFECTED PRODUCTS

vendor:redhatmodel:enterprise linuxscope:eqversion:8.0

Trust: 1.0

vendor:redhatmodel:quayscope:eqversion:3.0.0

Trust: 1.0

vendor:synologymodel:skynasscope:eqversion: -

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:16.04

Trust: 1.0

vendor:redhatmodel:openshift service meshscope:eqversion:1.0

Trust: 1.0

vendor:f5model:nginxscope:gteversion:1.9.5

Trust: 1.0

vendor:f5model:nginxscope:gteversion:1.17.0

Trust: 1.0

vendor:fedoraprojectmodel:fedorascope:eqversion:30

Trust: 1.0

vendor:synologymodel:diskstation managerscope:eqversion:6.2

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:gteversion:7.8.2.0

Trust: 1.0

vendor:oraclemodel:enterprise communications brokerscope:eqversion:3.2.0

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:18.04

Trust: 1.0

vendor:applemodel:swiftnioscope:lteversion:1.4.0

Trust: 1.0

vendor:applemodel:swiftnioscope:gteversion:1.0.0

Trust: 1.0

vendor:apachemodel:traffic serverscope:gteversion:8.0.0

Trust: 1.0

vendor:fedoraprojectmodel:fedorascope:eqversion:29

Trust: 1.0

vendor:nodejsmodel:node.jsscope:gteversion:10.0.0

Trust: 1.0

vendor:nodejsmodel:node.jsscope:gteversion:10.13.0

Trust: 1.0

vendor:apachemodel:traffic serverscope:gteversion:7.0.0

Trust: 1.0

vendor:debianmodel:linuxscope:eqversion:10.0

Trust: 1.0

vendor:oraclemodel:enterprise communications brokerscope:eqversion:3.1.0

Trust: 1.0

vendor:opensusemodel:leapscope:eqversion:15.1

Trust: 1.0

vendor:nodejsmodel:node.jsscope:ltversion:12.8.1

Trust: 1.0

vendor:apachemodel:traffic serverscope:gteversion:6.0.0

Trust: 1.0

vendor:nodejsmodel:node.jsscope:lteversion:8.8.1

Trust: 1.0

vendor:nodejsmodel:node.jsscope:ltversion:10.16.3

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:gteversion:7.7.2.0

Trust: 1.0

vendor:nodejsmodel:node.jsscope:gteversion:8.0.0

Trust: 1.0

vendor:redhatmodel:jboss enterprise application platformscope:eqversion:7.2.0

Trust: 1.0

vendor:f5model:nginxscope:lteversion:1.17.2

Trust: 1.0

vendor:nodejsmodel:node.jsscope:gteversion:12.0.0

Trust: 1.0

vendor:synologymodel:vs960hdscope:eqversion: -

Trust: 1.0

vendor:oraclemodel:graalvmscope:eqversion:19.2.0

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:ltversion:7.8.2.13

Trust: 1.0

vendor:nodejsmodel:node.jsscope:ltversion:8.16.1

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:19.04

Trust: 1.0

vendor:opensusemodel:leapscope:eqversion:15.0

Trust: 1.0

vendor:redhatmodel:jboss core servicesscope:eqversion:1.0

Trust: 1.0

vendor:nodejsmodel:node.jsscope:lteversion:10.12.0

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:ltversion:8.2.0

Trust: 1.0

vendor:apachemodel:traffic serverscope:lteversion:7.1.6

Trust: 1.0

vendor:apachemodel:traffic serverscope:lteversion:6.2.3

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:gteversion:8.1.0

Trust: 1.0

vendor:redhatmodel:software collectionsscope:eqversion:1.0

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:ltversion:7.7.2.24

Trust: 1.0

vendor:nodejsmodel:node.jsscope:gteversion:8.9.0

Trust: 1.0

vendor:f5model:nginxscope:ltversion:1.16.1

Trust: 1.0

vendor:redhatmodel:jboss enterprise application platformscope:eqversion:7.3.0

Trust: 1.0

vendor:apachemodel:traffic serverscope:lteversion:8.0.3

Trust: 1.0

vendor:debianmodel:linuxscope:eqversion:9.0

Trust: 1.0

vendor:akamaimodel: - scope: - version: -

Trust: 0.8

vendor:amazonmodel: - scope: - version: -

Trust: 0.8

vendor:apache traffic servermodel: - scope: - version: -

Trust: 0.8

vendor:applemodel: - scope: - version: -

Trust: 0.8

vendor:cloudflaremodel: - scope: - version: -

Trust: 0.8

vendor:envoymodel: - scope: - version: -

Trust: 0.8

vendor:facebookmodel: - scope: - version: -

Trust: 0.8

vendor:go programming languagemodel: - scope: - version: -

Trust: 0.8

vendor:litespeedmodel: - scope: - version: -

Trust: 0.8

vendor:microsoftmodel: - scope: - version: -

Trust: 0.8

vendor:nettymodel: - scope: - version: -

Trust: 0.8

vendor:node jsmodel: - scope: - version: -

Trust: 0.8

vendor:synologymodel: - scope: - version: -

Trust: 0.8

vendor:twistedmodel: - scope: - version: -

Trust: 0.8

vendor:ubuntumodel: - scope: - version: -

Trust: 0.8

vendor:grpcmodel: - scope: - version: -

Trust: 0.8

vendor:nghttp2model: - scope: - version: -

Trust: 0.8

vendor:nginxmodel: - scope: - version: -

Trust: 0.8

sources: CERT/CC: VU#605641 // NVD: CVE-2019-9511

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-9511
value: HIGH

Trust: 1.0

cret@cert.org: CVE-2019-9511
value: HIGH

Trust: 1.0

CNNVD: CNNVD-201908-924
value: HIGH

Trust: 0.6

VULHUB: VHN-160946
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2019-9511
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-160946
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-9511
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

cret@cert.org: CVE-2019-9511
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.0

sources: VULHUB: VHN-160946 // CNNVD: CNNVD-201908-924 // NVD: CVE-2019-9511 // NVD: CVE-2019-9511

PROBLEMTYPE DATA

problemtype:CWE-400

Trust: 1.1

problemtype:CWE-770

Trust: 1.1

sources: VULHUB: VHN-160946 // NVD: CVE-2019-9511

THREAT TYPE

remote

Trust: 0.8

sources: PACKETSTORM: 178284 // PACKETSTORM: 180394 // CNNVD: CNNVD-201908-924

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201908-924

PATCH

title:HTTP/2 Remedial measures to achieve security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=96609

Trust: 0.6

sources: CNNVD: CNNVD-201908-924

EXTERNAL IDS

db:NVDid:CVE-2019-9511

Trust: 2.6

db:CERT/CCid:VU#605641

Trust: 2.5

db:MCAFEEid:SB10296

Trust: 1.7

db:PACKETSTORMid:158636

Trust: 0.8

db:PACKETSTORMid:154117

Trust: 0.7

db:CNNVDid:CNNVD-201908-924

Trust: 0.7

db:PACKETSTORMid:157214

Trust: 0.7

db:PACKETSTORMid:158095

Trust: 0.7

db:AUSCERTid:ESB-2019.3116

Trust: 0.6

db:AUSCERTid:ESB-2020.2071

Trust: 0.6

db:AUSCERTid:ESB-2019.4788

Trust: 0.6

db:AUSCERTid:ESB-2020.1544

Trust: 0.6

db:AUSCERTid:ESB-2019.3129

Trust: 0.6

db:AUSCERTid:ESB-2020.2588

Trust: 0.6

db:AUSCERTid:ESB-2019.4343

Trust: 0.6

db:AUSCERTid:ESB-2019.3597.3

Trust: 0.6

db:AUSCERTid:ESB-2019.4645

Trust: 0.6

db:AUSCERTid:ESB-2019.4403

Trust: 0.6

db:AUSCERTid:ESB-2020.1335

Trust: 0.6

db:AUSCERTid:ESB-2019.3597.2

Trust: 0.6

db:AUSCERTid:ESB-2020.1766

Trust: 0.6

db:AUSCERTid:ESB-2019.4484

Trust: 0.6

db:AUSCERTid:ESB-2020.0100

Trust: 0.6

db:AUSCERTid:ESB-2020.1030

Trust: 0.6

db:PACKETSTORMid:155484

Trust: 0.6

db:PACKETSTORMid:155414

Trust: 0.6

db:PACKETSTORMid:156852

Trust: 0.6

db:PACKETSTORMid:157741

Trust: 0.6

db:NSFOCUSid:43918

Trust: 0.6

db:PACKETSTORMid:154725

Trust: 0.2

db:PACKETSTORMid:154533

Trust: 0.2

db:PACKETSTORMid:154284

Trust: 0.1

db:PACKETSTORMid:154693

Trust: 0.1

db:PACKETSTORMid:154401

Trust: 0.1

db:PACKETSTORMid:154712

Trust: 0.1

db:PACKETSTORMid:154510

Trust: 0.1

db:PACKETSTORMid:154663

Trust: 0.1

db:PACKETSTORMid:154471

Trust: 0.1

db:PACKETSTORMid:154699

Trust: 0.1

db:PACKETSTORMid:154190

Trust: 0.1

db:PACKETSTORMid:154470

Trust: 0.1

db:PACKETSTORMid:154848

Trust: 0.1

db:VULHUBid:VHN-160946

Trust: 0.1

db:PACKETSTORMid:155417

Trust: 0.1

db:PACKETSTORMid:155483

Trust: 0.1

db:PACKETSTORMid:178284

Trust: 0.1

db:PACKETSTORMid:180394

Trust: 0.1

sources: CERT/CC: VU#605641 // VULHUB: VHN-160946 // PACKETSTORM: 155417 // PACKETSTORM: 158636 // PACKETSTORM: 157214 // PACKETSTORM: 154533 // PACKETSTORM: 155483 // PACKETSTORM: 154725 // PACKETSTORM: 158095 // PACKETSTORM: 178284 // PACKETSTORM: 180394 // CNNVD: CNNVD-201908-924 // NVD: CVE-2019-9511

REFERENCES

url:https://github.com/netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md

Trust: 2.5

url:https://www.synology.com/security/advisory/synology_sa_19_33

Trust: 2.5

url:https://access.redhat.com/errata/rhsa-2019:3932

Trust: 2.4

url:https://access.redhat.com/errata/rhsa-2019:4018

Trust: 2.4

url:https://access.redhat.com/errata/rhsa-2019:3933

Trust: 2.3

url:https://access.redhat.com/errata/rhsa-2019:3935

Trust: 2.3

url:https://access.redhat.com/errata/rhsa-2019:4019

Trust: 2.3

url:https://access.redhat.com/errata/rhsa-2019:4020

Trust: 2.3

url:https://access.redhat.com/errata/rhsa-2019:4021

Trust: 2.3

url:https://usn.ubuntu.com/4099-1/

Trust: 2.3

url:https://access.redhat.com/errata/rhsa-2019:2799

Trust: 1.8

url:https://access.redhat.com/errata/rhsa-2019:2966

Trust: 1.8

url:https://seclists.org/bugtraq/2019/aug/40

Trust: 1.7

url:https://seclists.org/bugtraq/2019/sep/1

Trust: 1.7

url:https://kb.cert.org/vuls/id/605641/

Trust: 1.7

url:https://security.netapp.com/advisory/ntap-20190823-0002/

Trust: 1.7

url:https://security.netapp.com/advisory/ntap-20190823-0005/

Trust: 1.7

url:https://www.debian.org/security/2019/dsa-4505

Trust: 1.7

url:https://www.debian.org/security/2019/dsa-4511

Trust: 1.7

url:https://www.debian.org/security/2020/dsa-4669

Trust: 1.7

url:https://www.oracle.com/security-alerts/cpujan2021.html

Trust: 1.7

url:https://www.oracle.com/security-alerts/cpuoct2020.html

Trust: 1.7

url:https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html

Trust: 1.7

url:https://access.redhat.com/errata/rhsa-2019:2692

Trust: 1.7

url:https://access.redhat.com/errata/rhsa-2019:2745

Trust: 1.7

url:https://access.redhat.com/errata/rhsa-2019:2746

Trust: 1.7

url:https://access.redhat.com/errata/rhsa-2019:2775

Trust: 1.7

url:https://access.redhat.com/errata/rhsa-2019:2925

Trust: 1.7

url:https://access.redhat.com/errata/rhsa-2019:2939

Trust: 1.7

url:https://access.redhat.com/errata/rhsa-2019:2949

Trust: 1.7

url:https://access.redhat.com/errata/rhsa-2019:2955

Trust: 1.7

url:https://access.redhat.com/errata/rhsa-2019:3041

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00003.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00005.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00014.html

Trust: 1.7

url:https://blogs.akamai.com/sitr/2019/08/http2-vulnerabilities.html

Trust: 1.6

url:https://kc.mcafee.com/corporate/index?page=content&id=sb10296

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2019-9511

Trust: 1.5

url:https://support.f5.com/csp/article/k02591030

Trust: 1.1

url:https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/bp556leg3wenhzi5taq6zebftjb4e2is/

Trust: 1.0

url:https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/jubyaf6ed3o4xchq5c2hyenjlxyxzc4m/

Trust: 1.0

url:https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/lzluypyy3rx4zjdwzrjiksulyrj4pxw7/

Trust: 1.0

url:https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/popaec4fwl4uu4ldegpy5npalu24ffqd/

Trust: 1.0

url:https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/tazzevtcn2b4wt6aibj7xgyjmbtorju5/

Trust: 1.0

url:https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/xhtku7yq5eep2xnsav4m4vj7qcbojmod/

Trust: 1.0

url:https://support.f5.com/csp/article/k02591030?utm_source=f5support&amp%3butm_medium=rss

Trust: 1.0

url:https://vuls.cert.org/confluence/pages/viewpage.action?pageid=56393752

Trust: 0.8

url:https://tools.ietf.org/html/rfc7540

Trust: 0.8

url:https://tools.ietf.org/html/rfc7541

Trust: 0.8

url:https://blog.cloudflare.com/on-the-recent-http-2-dos-attacks/

Trust: 0.8

url:https://blog.litespeedtech.com/2019/08/15/litespeed-addresses-http-2-dos-advisories/

Trust: 0.8

url:https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/cve-2019-9511https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/cve-2019-9512https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/cve-2019-9513https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/cve-2019-9514https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/cve-2019-9518

Trust: 0.8

url:https://access.redhat.com/security/updates/classification/#important

Trust: 0.8

url:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/bp556leg3wenhzi5taq6zebftjb4e2is/

Trust: 0.7

url:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/xhtku7yq5eep2xnsav4m4vj7qcbojmod/

Trust: 0.7

url:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/popaec4fwl4uu4ldegpy5npalu24ffqd/

Trust: 0.7

url:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/lzluypyy3rx4zjdwzrjiksulyrj4pxw7/

Trust: 0.7

url:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/jubyaf6ed3o4xchq5c2hyenjlxyxzc4m/

Trust: 0.7

url:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/tazzevtcn2b4wt6aibj7xgyjmbtorju5/

Trust: 0.7

url:https://access.redhat.com/security/cve/cve-2019-9511

Trust: 0.7

url:https://access.redhat.com/security/team/contact/

Trust: 0.7

url:https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.7

url:https://bugzilla.redhat.com/):

Trust: 0.7

url:http2-cves/

Trust: 0.6

url:https://www.cloudfoundry.org/blog/various-

Trust: 0.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-9518

Trust: 0.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-9517

Trust: 0.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-9516

Trust: 0.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-9515

Trust: 0.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-9514

Trust: 0.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-9513

Trust: 0.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-9512

Trust: 0.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-9511

Trust: 0.6

url:https://support.f5.com/csp/article/k02591030?utm_source=f5support&utm_medium=rss

Trust: 0.6

url:https://support.f5.com/csp/article/k50233772

Trust: 0.6

url:http://mailman.nginx.org/pipermail/nginx-announce/2019/000249.html

Trust: 0.6

url:https://www.suse.com/support/update/announcement/2019/suse-su-201914246-1.html

Trust: 0.6

url:https://security.business.xerox.com/wp-content/uploads/2019/11/cert_xrx19-029_ffpsv2_win10_securitybulletin_nov2019.pdf

Trust: 0.6

url:https://www.suse.com/support/update/announcement/2020/suse-su-20200059-1.html

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.1544/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.2071/

Trust: 0.6

url:https://packetstormsecurity.com/files/158636/red-hat-security-advisory-2020-3192-01.html

Trust: 0.6

url:https://packetstormsecurity.com/files/157214/red-hat-security-advisory-2020-1445-01.html

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2019.4645/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2019.4403/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2019.3597.2/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2019.4788/

Trust: 0.6

url:https://pivotal.io/security/cve-2019-9517

Trust: 0.6

url:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-node-js-affect-ibm-spectrum-protect-plus-cve-2019-15606-cve-2019-15604-cve-2019-15605-cve-2019-9511-cve-2019-9516-cve-2019-9512-cve-2019-9517-cve-2019-951/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2019.4484/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.2588/

Trust: 0.6

url:https://www.ibm.com/support/pages/node/1143454

Trust: 0.6

url:https://packetstormsecurity.com/files/154117/ubuntu-security-notice-usn-4099-1.html

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2019.3116/

Trust: 0.6

url:https://packetstormsecurity.com/files/156852/red-hat-security-advisory-2020-0922-01.html

Trust: 0.6

url:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-kubernetes-affect-ibm-infosphere-information-server/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.1766/

Trust: 0.6

url:https://portal.msrc.microsoft.com/zh-cn/security-guidance/advisory/cve-2019-9511

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.1335/

Trust: 0.6

url:https://packetstormsecurity.com/files/157741/red-hat-security-advisory-2020-2067-01.html

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2019.3597.3/

Trust: 0.6

url:https://packetstormsecurity.com/files/158095/red-hat-security-advisory-2020-2565-01.html

Trust: 0.6

url:https://packetstormsecurity.com/files/155414/red-hat-security-advisory-2019-3935-01.html

Trust: 0.6

url:https://www.ibm.com/support/pages/node/1150960

Trust: 0.6

url:https://www.ibm.com/support/pages/node/1137466

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2019.4343/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.0100/

Trust: 0.6

url:http://www.nsfocus.net/vulndb/43918

Trust: 0.6

url:https://www.ibm.com/support/pages/node/1167160

Trust: 0.6

url:https://vigilance.fr/vulnerability/http-2-multiple-vulnerabilities-30040

Trust: 0.6

url:https://packetstormsecurity.com/files/155484/red-hat-security-advisory-2019-4019-01.html

Trust: 0.6

url:https://www.ibm.com/blogs/psirt/security-bulletin-vyatta-5600-vrouter-software-patches-release-1801-ze-2/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2019.3129/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.1030/

Trust: 0.6

url:https://nvd.nist.gov/vuln/detail/cve-2019-9513

Trust: 0.4

url:https://access.redhat.com/security/cve/cve-2019-9516

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2019-9516

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2019-9514

Trust: 0.4

url:https://access.redhat.com/security/cve/cve-2019-9512

Trust: 0.4

url:https://access.redhat.com/security/cve/cve-2019-9514

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2019-9512

Trust: 0.4

url:https://access.redhat.com/articles/11258

Trust: 0.3

url:https://access.redhat.com/security/cve/cve-2019-9513

Trust: 0.3

url:https://access.redhat.com/security/team/key/

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2019-9515

Trust: 0.3

url:https://access.redhat.com/security/cve/cve-2019-9515

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2019-9517

Trust: 0.2

url:https://access.redhat.com/security/cve/cve-2019-9517

Trust: 0.2

url:https://access.redhat.com/security/cve/cve-2020-11619

Trust: 0.2

url:https://access.redhat.com/security/cve/cve-2019-20444

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2019-20445

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2019-20444

Trust: 0.2

url:https://access.redhat.com/security/cve/cve-2019-20445

Trust: 0.2

url:https://access.redhat.com/security/cve/cve-2020-7238

Trust: 0.2

url:https://access.redhat.com/security/cve/cve-2020-11620

Trust: 0.2

url:https://access.redhat.com/security/cve/cve-2019-14838

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2019-14838

Trust: 0.2

url:https://kc.mcafee.com/corporate/index?page=content&amp;id=sb10296

Trust: 0.1

url:https://support.f5.com/csp/article/k02591030?utm_source=f5support&amp;amp;utm_medium=rss

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-0197

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-5407

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-17199

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-17189

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2018-0737

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2018-17199

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-0737

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-0217

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-0734

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-0217

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-0197

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2018-17189

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2018-5407

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-0196

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-0196

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2018-0734

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-16335

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-11797

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-11112

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-11113

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-10968

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-9546

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-14060

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-16943

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-10672

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-17573

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-10172

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-10672

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-20330

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-12086

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2018-1000632

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-1000632

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-12400

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2018-3831

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-0231

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-20330

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2018-11797

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-10673

Trust: 0.1

url:https://access.redhat.com/jbossnetwork/restricted/listsoftware.html?downloadtype=distributions&product=jboss.fuse&version=7.7.0

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-17531

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-16335

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-10086

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-14062

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2018-12541

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-3797

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2016-4970

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-17531

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-9827

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-14540

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-17267

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-1745

Trust: 0.1

url:https://access.redhat.com/documentation/en-us/red_hat_fuse/7.7/

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-10172

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-12086

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-16942

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-14892

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-4970

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-9548

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-1953

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-1757

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-16943

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-10969

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-0231

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-17267

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-14893

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-11111

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-9827

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-9547

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-17573

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-16942

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-14893

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-3831

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-14888

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-12400

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-14892

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-14061

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-10086

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-12541

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-14540

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-8840

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2020:3192

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-14195

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-3797

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-14888

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-0222

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-10247

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-9518

Trust: 0.1

url:https://access.redhat.com/jbossnetwork/restricted/listsoftware.html?downloadtype=distributions&product=jboss.amq.broker&version=7.4.3

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-16869

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-0222

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-7238

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2020:1445

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-10241

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-10247

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-16869

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-10241

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-9518

Trust: 0.1

url:https://access.redhat.com/documentation/en-us/red_hat_amq/7.4/

Trust: 0.1

url:https://issues.jboss.org/):

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-14843

Trust: 0.1

url:https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.2/html-single/installation_guide/

Trust: 0.1

url:https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.2/

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-14843

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-11620

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2020:2565

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-11619

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-19343

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-3805

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-19343

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-3805

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/nghttp2/1.40.0-1ubuntu0.3

Trust: 0.1

url:https://ubuntu.com/security/notices/usn-6754-1

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-44487

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/nghttp2/1.43.0-1ubuntu0.2

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/nghttp2/1.55.1-1ubuntu0.2

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2024-28182

Trust: 0.1

url:https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.1/html-single/installation_guide/index

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=1703469

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=1752980

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=1807305

Trust: 0.1

url:https://issues.redhat.com/browse/jbeap-24826

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2024:5856

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=1752770

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=1735745

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=1735744

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=1737517

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=1798524

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=2041949

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=2031667

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=1725807

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=1758619

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=1793970

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=2041959

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=1798509

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=2041967

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=1772464

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=1775293

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=1767483

Trust: 0.1

url:https://access.redhat.com/security/data/csaf/v2/advisories/2024/rhsa-2024_5856.json

Trust: 0.1

url:https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.1

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=1741860

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=1735645

Trust: 0.1

sources: CERT/CC: VU#605641 // VULHUB: VHN-160946 // PACKETSTORM: 155417 // PACKETSTORM: 158636 // PACKETSTORM: 157214 // PACKETSTORM: 154533 // PACKETSTORM: 155483 // PACKETSTORM: 154725 // PACKETSTORM: 158095 // PACKETSTORM: 178284 // PACKETSTORM: 180394 // CNNVD: CNNVD-201908-924 // NVD: CVE-2019-9511

CREDITS

Red Hat

Trust: 0.8

sources: PACKETSTORM: 155417 // PACKETSTORM: 158636 // PACKETSTORM: 157214 // PACKETSTORM: 154533 // PACKETSTORM: 155483 // PACKETSTORM: 154725 // PACKETSTORM: 158095 // PACKETSTORM: 180394

SOURCES

db:CERT/CCid:VU#605641
db:VULHUBid:VHN-160946
db:PACKETSTORMid:155417
db:PACKETSTORMid:158636
db:PACKETSTORMid:157214
db:PACKETSTORMid:154533
db:PACKETSTORMid:155483
db:PACKETSTORMid:154725
db:PACKETSTORMid:158095
db:PACKETSTORMid:178284
db:PACKETSTORMid:180394
db:CNNVDid:CNNVD-201908-924
db:NVDid:CVE-2019-9511

LAST UPDATE DATE

2024-11-07T20:47:50.924000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#605641date:2019-11-19T00:00:00
db:VULHUBid:VHN-160946date:2020-10-22T00:00:00
db:CNNVDid:CNNVD-201908-924date:2021-04-14T00:00:00
db:NVDid:CVE-2019-9511date:2023-11-07T03:13:41.610

SOURCES RELEASE DATE

db:CERT/CCid:VU#605641date:2019-08-13T00:00:00
db:VULHUBid:VHN-160946date:2019-08-13T00:00:00
db:PACKETSTORMid:155417date:2019-11-20T21:11:11
db:PACKETSTORMid:158636date:2020-07-29T00:05:59
db:PACKETSTORMid:157214date:2020-04-14T15:39:41
db:PACKETSTORMid:154533date:2019-09-19T16:28:51
db:PACKETSTORMid:155483date:2019-11-27T15:43:06
db:PACKETSTORMid:154725date:2019-10-03T20:31:49
db:PACKETSTORMid:158095date:2020-06-16T00:54:44
db:PACKETSTORMid:178284date:2024-04-26T15:13:40
db:PACKETSTORMid:180394date:2024-08-27T14:58:09
db:CNNVDid:CNNVD-201908-924date:2019-08-13T00:00:00
db:NVDid:CVE-2019-9511date:2019-08-13T21:15:12.223