Red Hat Fuse Integration Services provides a set of tools and containerized xPaaS images that enable development, deployment, and management of integration microservices within OpenShift.
Security fix(es):
jackson-databind: incomplete fix for CVE-2017-7525 permits unsafe serialization via c3p0 libraries (CVE-2018-7489)
spring-framework: Address partial fix for CVE-2018-1270 (CVE-2018-1275)
spring-framework: Directory traversal vulnerability with static resources on Windows filesystems (CVE-2018-1271)
spring-framework: Possible RCE via spring messaging (CVE-2018-1270)
spring-security-oauth: remote code execution in the authorization process (CVE-2018-1260)
tomcat: A bug in the UTF-8 decoder can lead to DoS (CVE-2018-1336)
tomcat: Incorrect handling of empty string URL in security constraints can lead to unintended exposure of resources (CVE-2018-1304)
tomcat: Late application of security constraints can lead to resource exposure for unauthorised users (CVE-2018-1305)
tomcat: Remote Code Execution bypass for CVE-2017-12615 (CVE-2017-12617)
For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.