Red Hat Fuse Integration Services provides a set of tools and containerized xPaaS images that enable development, deployment, and management of integration microservices within OpenShift.
Security fix(es):
jackson-databind: Potential information exfiltration with default typing, serialization gadget from MyBatis (CVE-2018-11307)
jackson-databind: improper polymorphic deserialization of types from Jodd-db library (CVE-2018-12022)
jackson-databind: improper polymorphic deserialization of types from Oracle JDBC driver (CVE-2018-12023)
jackson-databind: arbitrary code execution in slf4j-ext class (CVE-2018-14718)
jackson-databind: arbitrary code execution in blaze-ds-opt and blaze-ds-core classes (CVE-2018-14719)
jackson-databind: improper polymorphic deserialization in axis2-transport-jms class (CVE-2018-19360)
jackson-databind: improper polymorphic deserialization in openjpa class (CVE-2018-19361)
jackson-databind: improper polymorphic deserialization in jboss-common-core class (CVE-2018-19362)
For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.