[RHSA-2013:1844-01] Important: Red Hat JBoss Web Framework Kit 2.4.0 update

bugzilla at redhat.com bugzilla at redhat.com
Mon Dec 16 18:49:02 UTC 2013


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Important: Red Hat JBoss Web Framework Kit 2.4.0 update
Advisory ID:       RHSA-2013:1844-01
Product:           Red Hat JBoss Web Framework Kit
Advisory URL:      https://rhn.redhat.com/errata/RHSA-2013-1844.html
Issue date:        2013-12-16
CVE Names:         CVE-2012-6612 CVE-2013-6397 CVE-2013-6407 
                   CVE-2013-6408 
=====================================================================

1. Summary:

An update for the solr-core component of Red Hat JBoss Web Framework Kit
2.4.0 that fixes multiple security issues is now available from the Red Hat
Customer Portal.

The Red Hat Security Response Team has rated this update as having
important security impact. A Common Vulnerability Scoring System (CVSS)
base score, which gives a detailed severity rating, is available from the
CVE link in the References section.

2. Description:

Red Hat JBoss Web Framework Kit combines popular open source web frameworks
into a single solution for Java applications. The Apache Solr component is
an open-source search server based on the Lucene Java search library.

It was found that the SolrResourceLoader class in Apache Solr allowed
loading of resources via absolute paths, or relative paths which were not
sanitized for directory traversal. Some Solr components expose REST
interfaces which load resources (XSL style sheets and Velocity templates)
via SolrResourceLoader, using paths identified by REST parameters. A remote
attacker could use this flaw to load arbitrary local files on the server
via SolrResourceLoader, potentially resulting in information disclosure or
remote code execution. (CVE-2013-6397)

It was found that the XML and XSLT UpdateRequestHandler classes in Apache
Solr would resolve external entities, allowing an attacker to conduct XML
External Entity (XXE) attacks. A remote attacker could use this flaw to
read files accessible to the user running the application server, and
potentially perform other more advanced XXE attacks. (CVE-2012-6612,
CVE-2013-6407)

It was found that the DocumentAnalysisRequestHandler class in Apache Solr
would resolve external entities, allowing an attacker to conduct XXE
attacks. A remote attacker could use this flaw to read files accessible to
the user running the application server, and potentially perform other more
advanced XXE attacks. (CVE-2013-6408)

All users of Red Hat JBoss Web Framework Kit 2.4.0 as provided from the Red
Hat Customer Portal are advised to apply this update.

3. Solution:

The References section of this erratum contains a download link (you must
log in to download the update). Before applying this update, back up your
existing installation of Red Hat JBoss Web Framework Kit.

The JBoss server process must be restarted for this update to take effect.

4. Bugs fixed (https://bugzilla.redhat.com/):

1035062 - CVE-2013-6397 Apache Solr: directory traversal when loading XSL stylesheets and Velocity templates
1035981 - CVE-2012-6612 CVE-2013-6407 Apache Solr: XML eXternal Entity (XXE) flaw in XML and XSLT UpdateRequestHandler
1035985 - CVE-2013-6408 Apache Solr: XML eXternal Entity (XXE) flaw in DocumentAnalysisRequestHandler

5. References:

https://www.redhat.com/security/data/cve/CVE-2012-6612.html
https://www.redhat.com/security/data/cve/CVE-2013-6397.html
https://www.redhat.com/security/data/cve/CVE-2013-6407.html
https://www.redhat.com/security/data/cve/CVE-2013-6408.html
https://access.redhat.com/security/updates/classification/#important
https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=web.framework.kit&downloadType=securityPatches&version=2.4.0

6. Contact:

The Red Hat security contact is <secalert at redhat.com>.  More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2013 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (GNU/Linux)

iD8DBQFSr0sCXlSAg2UNWIIRAm81AJwOh+KZhUtBmUUD+Zr0G0DMB3eIngCglEtY
/l1L3Y/WsCgx4bWB4x4CZmc=
=0m1B
-----END PGP SIGNATURE-----





More information about the Jboss-watch-list mailing list