Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1101619 - (CVE-2014-0248) CVE-2014-0248 JBoss Seam: RCE via unsafe logging in AuthenticationFilter
CVE-2014-0248 JBoss Seam: RCE via unsafe logging in AuthenticationFilter
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20140623,repo...
: Security
Depends On: 1101741 1101742 1101743 1101744 1101745 1101746 1101747 1101748 1101749 1101750 1101752 1101753 1101754 1101755 1101785 1101786 1101787 1101788 1101789 1101790 1101791 1101792 1102383 1102384
Blocks: 1101620 1103918 1103922 1108737 1109835 1112044 1244362 1244363
  Show dependency treegraph
 
Reported: 2014-05-27 11:40 EDT by Arun Babu Neelicattu
Modified: 2016-09-07 07:35 EDT (History)
56 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
It was found that the org.jboss.seam.web.AuthenticationFilter class implementation did not properly use Seam logging. A remote attacker could send specially crafted authentication headers to an application, which could result in arbitrary code execution with the privileges of the user running that application.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2016-03-10 16:30:06 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2014:0785 normal SHIPPED_LIVE Important: Red Hat JBoss Web Framework Kit 2.5.0 security update 2014-06-23 18:02:30 EDT
Red Hat Product Errata RHSA-2014:0791 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Web Platform 5.2.0 security update 2014-06-25 15:50:51 EDT
Red Hat Product Errata RHSA-2014:0792 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Web Platform 5.2.0 security update 2014-06-25 16:01:14 EDT
Red Hat Product Errata RHSA-2014:0793 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform 5.2.0 security update 2014-06-25 16:00:59 EDT
Red Hat Product Errata RHSA-2014:0794 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform 5.2.0 security update 2014-06-25 15:50:45 EDT
Red Hat Product Errata RHSA-2015:1888 normal SHIPPED_LIVE Important: Red Hat JBoss SOA Platform 5.3.1 security update 2015-10-12 15:27:33 EDT

  None (edit)
Description Arun Babu Neelicattu 2014-05-27 11:40:54 EDT
It was found that org.jboss.seam.web.AuthenticationFilter class implementation used seam logging in an unsafe manner. A remote attacker could exploit this issue in order to gain arbitrary code execution by providing specifically crafted authentication headers.
Comment 7 Arun Babu Neelicattu 2014-06-23 09:57:09 EDT
Acknowledgements:

This issue was discovered by Marek Schmidt of Red Hat.
Comment 8 errata-xmlrpc 2014-06-23 14:02:38 EDT
This issue has been addressed in following products:

  Red Hat JBoss Web Framework Kit 2.5.0

Via RHSA-2014:0785 https://rhn.redhat.com/errata/RHSA-2014-0785.html
Comment 9 errata-xmlrpc 2014-06-25 11:51:30 EDT
This issue has been addressed in following products:

  JBoss Enterprise Application Platform 5.2.0 

Via RHSA-2014:0794 https://rhn.redhat.com/errata/RHSA-2014-0794.html
Comment 10 errata-xmlrpc 2014-06-25 11:52:10 EDT
This issue has been addressed in following products:

  JBoss Enterprise Web Platform 5.2.0

Via RHSA-2014:0791 https://rhn.redhat.com/errata/RHSA-2014-0791.html
Comment 11 errata-xmlrpc 2014-06-25 12:02:28 EDT
This issue has been addressed in following products:

  JBEAP 5 for RHEL 5
  JBEAP 5 for RHEL 4
  JBEAP 5 for RHEL 6

Via RHSA-2014:0793 https://rhn.redhat.com/errata/RHSA-2014-0793.html
Comment 12 errata-xmlrpc 2014-06-25 12:02:33 EDT
This issue has been addressed in following products:

  JBEWP 5 for RHEL 5
  JBEWP 5 for RHEL 4
  JBEWP 5 for RHEL 6

Via RHSA-2014:0792 https://rhn.redhat.com/errata/RHSA-2014-0792.html
Comment 16 errata-xmlrpc 2015-10-12 11:28:07 EDT
This issue has been addressed in the following products:

  Red Hat JBoss SOA Platform 5.3.1

Via RHSA-2015:1888 https://rhn.redhat.com/errata/RHSA-2015-1888.html

Note You need to log in before you can comment on or make changes to this bug.