Bug 1824301 (CVE-2020-1954)

Summary: CVE-2020-1954 cxf: JMX integration is vulnerable to a MITM attack
Product: [Other] Security Response Reporter: Guilherme de Almeida Suckevicz <gsuckevi>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: aboyko, aileenc, akoufoud, alazarot, almorale, anstephe, asoldano, atangrin, avibelli, bbaranow, bgeorges, bmaxwell, brian.stansberry, cdewolf, chazlett, cmoulliard, darran.lofthouse, dkreling, dosoudil, drieden, etirelli, extras-orphan, ggaughan, gmalinko, ibek, ikanello, iweiss, janstey, jawilson, jbalunas, jochrist, jpallich, jperkins, jstastny, jwon, krathod, kverlaen, kwills, lef, lgao, lthon, mnovotny, msochure, msvehla, mszynkie, nwallace, paradhya, pdrozd, pgallagh, pjindal, pmackay, psotirop, puntogil, rguimara, rrajasek, rruss, rstancel, rsvoboda, rsynek, sdaley, smaestri, sthorger, tom.jenkinson
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-08-31 19:17:29 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1824302    
Bug Blocks: 1824303    

Description Guilherme de Almeida Suckevicz 2020-04-15 18:44:07 UTC
Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory’ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.

Reference:
http://cxf.apache.org/security-advisories.data/CVE-2020-1954.txt.asc?version=1&modificationDate=1585730169000&api=v2

Comment 1 Guilherme de Almeida Suckevicz 2020-04-15 18:44:31 UTC
Created cxf tracking bugs for this issue:

Affects: fedora-30 [bug 1824302]

Comment 8 errata-xmlrpc 2020-08-31 15:41:10 UTC
This issue has been addressed in the following products:

  EAP-CD 20 Tech Preview

Via RHSA-2020:3585 https://access.redhat.com/errata/RHSA-2020:3585

Comment 9 Product Security DevOps Team 2020-08-31 19:17:29 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2020-1954

Comment 10 errata-xmlrpc 2020-10-13 16:48:18 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6

Via RHSA-2020:4244 https://access.redhat.com/errata/RHSA-2020:4244

Comment 11 errata-xmlrpc 2020-10-13 16:52:16 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8

Via RHSA-2020:4245 https://access.redhat.com/errata/RHSA-2020:4245

Comment 12 errata-xmlrpc 2020-10-13 16:56:39 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7

Via RHSA-2020:4246 https://access.redhat.com/errata/RHSA-2020:4246

Comment 13 errata-xmlrpc 2020-10-13 17:01:31 UTC
This issue has been addressed in the following products:

  EAP 7.3.3

Via RHSA-2020:4247 https://access.redhat.com/errata/RHSA-2020:4247

Comment 14 errata-xmlrpc 2020-11-04 19:24:22 UTC
This issue has been addressed in the following products:

  Red Hat Single Sign-On 7.4.3

Via RHSA-2020:4931 https://access.redhat.com/errata/RHSA-2020:4931

Comment 15 errata-xmlrpc 2020-11-05 18:47:32 UTC
This issue has been addressed in the following products:

  RHDM 7.9.0

Via RHSA-2020:4960 https://access.redhat.com/errata/RHSA-2020:4960

Comment 16 errata-xmlrpc 2020-11-05 18:48:59 UTC
This issue has been addressed in the following products:

  RHPAM 7.9.0

Via RHSA-2020:4961 https://access.redhat.com/errata/RHSA-2020:4961