Red Hat Bugzilla – Bug 1372120
CVE-2016-6346 RESTEasy: Abuse of GZIPInterceptor in RESTEasy can lead to denial of service attack
Last modified: 2018-10-19 17:37:19 EDT
It was found that GZIPInterceptor is enabled when not necessarily required in RESTEasy. An attacker could use this flaw to launch a Denial of Service attack.
Acknowledgments: Name: Mikhail Egorov (Odin)
Created resteasy tracking bugs for this issue: Affects: fedora-all [bug 1372122]
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 6.4.14 Via RHSA-2017:0517 https://rhn.redhat.com/errata/RHSA-2017-0517.html
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 Via RHSA-2017:0828 https://rhn.redhat.com/errata/RHSA-2017-0828.html
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Via RHSA-2017:0827 https://rhn.redhat.com/errata/RHSA-2017-0827.html
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5 Via RHSA-2017:0826 https://rhn.redhat.com/errata/RHSA-2017-0826.html
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Via RHSA-2017:0829 https://rhn.redhat.com/errata/RHSA-2017-0829.html
Statement: In order to reduce the risk of being exploited by this vulnerability, the default setting for RESTeasy was changed so that it no longer decodes requests with gzip compression. If it is desired to accept requests that are compressed with gzip compression, it must be re-enabled; details for how to do so are noted in the following KCS solution: https://access.redhat.com/solutions/2986611
Created resteasy tracking bugs for this issue: Affects: fedora-all [bug 1456313]
This issue has been addressed in the following products: Red Hat JBoss BRMS Via RHSA-2017:1676 https://access.redhat.com/errata/RHSA-2017:1676
This issue has been addressed in the following products: Red Hat JBoss BPM Suite Via RHSA-2017:1675 https://access.redhat.com/errata/RHSA-2017:1675
Created resteasy tracking bugs for this issue: Affects: fedora-all [bug 1471275]
Statement: This issue was fixed in EAP 7.1.0, but was not fixed in 7.0.7
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform Via RHSA-2018:0003 https://access.redhat.com/errata/RHSA-2018:0003
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Via RHSA-2018:0002 https://access.redhat.com/errata/RHSA-2018:0002
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Via RHSA-2018:0004 https://access.redhat.com/errata/RHSA-2018:0004
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Via RHSA-2018:0005 https://access.redhat.com/errata/RHSA-2018:0005
This issue has been addressed in the following products: Red Hat Decision Manager Via RHSA-2018:2143 https://access.redhat.com/errata/RHSA-2018:2143