Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1548909 - (CVE-2018-8088) CVE-2018-8088 slf4j: Deserialisation vulnerability in EventData constructor can allow for arbitrary code execution
CVE-2018-8088 slf4j: Deserialisation vulnerability in EventData constructor c...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20180222,repo...
: Security
Depends On: 1549929 1549387 1549388 1549389 1549390 1549391 1549928 1549930 1550336 1550337 1551840 1551843 1551844 1551845 1551846 1551848 1551849 1551850 1551851 1585897
Blocks: 1548912
  Show dependency treegraph
 
Reported: 2018-02-25 20:02 EST by Sam Fowler
Modified: 2018-10-19 17:46 EDT (History)
121 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
An XML deserialization vulnerability was discovered in slf4j's EventData, which accepts an XML serialized string and can lead to arbitrary code execution.
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:0582 None None None 2018-03-26 05:29 EDT
Red Hat Product Errata RHSA-2018:0592 None None None 2018-03-26 15:52 EDT
Red Hat Product Errata RHSA-2018:0627 None None None 2018-04-03 14:36 EDT
Red Hat Product Errata RHSA-2018:0628 None None None 2018-04-03 14:35 EDT
Red Hat Product Errata RHSA-2018:0629 None None None 2018-04-03 14:21 EDT
Red Hat Product Errata RHSA-2018:0630 None None None 2018-04-03 14:22 EDT
Red Hat Product Errata RHSA-2018:1247 None None None 2018-04-25 14:24 EDT
Red Hat Product Errata RHSA-2018:1248 None None None 2018-04-25 14:21 EDT
Red Hat Product Errata RHSA-2018:1249 None None None 2018-04-25 14:36 EDT
Red Hat Product Errata RHSA-2018:1251 None None None 2018-04-25 15:44 EDT
Red Hat Product Errata RHSA-2018:1323 None None None 2018-05-04 10:33 EDT
Red Hat Product Errata RHSA-2018:1447 None None None 2018-05-14 16:17 EDT
Red Hat Product Errata RHSA-2018:1448 None None None 2018-05-14 16:35 EDT
Red Hat Product Errata RHSA-2018:1449 None None None 2018-05-14 16:40 EDT
Red Hat Product Errata RHSA-2018:1450 None None None 2018-05-14 16:44 EDT
Red Hat Product Errata RHSA-2018:1451 None None None 2018-05-14 16:51 EDT
Red Hat Product Errata RHSA-2018:1525 None None None 2018-05-15 14:59 EDT
Red Hat Product Errata RHSA-2018:1575 None None None 2018-05-16 11:45 EDT
Red Hat Product Errata RHSA-2018:2143 None None None 2018-07-05 11:29 EDT
Red Hat Product Errata RHSA-2018:2419 None None None 2018-08-15 03:42 EDT
Red Hat Product Errata RHSA-2018:2420 None None None 2018-08-15 03:43 EDT
Red Hat Product Errata RHSA-2018:2669 None None None 2018-09-11 03:54 EDT
Red Hat Product Errata RHSA-2018:2930 None None None 2018-10-16 13:06 EDT

  None (edit)
Description Sam Fowler 2018-02-25 20:02:57 EST
SLF4J through version 1.7.25 is vulnerable to an XML deserialisation vulnerability in the EventData constructor.


Upstream Issue:

https://jira.qos.ch/browse/SLF4J-430
Comment 1 Sam Fowler 2018-02-25 20:03:37 EST
Acknowledgments:

Name: Chris McCown
Comment 4 Summer Long 2018-02-27 23:57:00 EST
Created slf4j tracking bugs for this issue:

Affects: fedora-all [bug 1549928]


Created slf4j-jboss-logmanager tracking bugs for this issue:

Affects: fedora-all [bug 1549929]
Comment 14 Kunjan Rathod 2018-03-21 19:54:34 EDT
The vulnerable code appears to be https://github.com/qos-ch/slf4j/blob/c960e8630cdf0ec4a6c5ea687ebe536e9e43ab68/slf4j-ext/src/main/java/org/slf4j/ext/EventData.java#L80, and it is not shipped in Vertx-3. Hence marking it as not affected.
Comment 15 Jason Shepherd 2018-03-21 19:56:52 EDT
Upstream have not fixed this issue yet. So I'm removing the fixed-in version value from this bug.

Ref: https://github.com/qos-ch/slf4j/blob/master/slf4j-ext/src/main/java/org/slf4j/ext/EventData.java
Comment 18 errata-xmlrpc 2018-03-26 05:29:05 EDT
This issue has been addressed in the following products:

  Red Hat Software Collections for Red Hat Enterprise Linux 7
  Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS
  Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS

Via RHSA-2018:0582 https://access.redhat.com/errata/RHSA-2018:0582
Comment 19 errata-xmlrpc 2018-03-26 15:51:52 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2018:0592 https://access.redhat.com/errata/RHSA-2018:0592
Comment 20 Doran Moppert 2018-04-03 03:05:21 EDT
Statement:

Subscription Asset Manager is now in a reduced support phase receiving only Critical impact security fixes. This issue has been rated as having a security impact of Important, and is not currently planned to be addressed in future updates.

This issue did not affect the versions of Candlepin as shipped with Red Hat Satellite 6 as Candlepin uses slf4j-api and not the affected slf4j-ext (which is not on the Candlepin classpath).

Red Hat Enterprise Virtualization Manager 4.1 is affected by this issue. Updated packages that address this issue are available through the Red Hat Enterprise Linux Server channels. Virtualization Manager hosts should be subscribed to these channels and obtain the updates via `yum update`.
Comment 21 errata-xmlrpc 2018-04-03 14:20:37 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2018:0629 https://access.redhat.com/errata/RHSA-2018:0629
Comment 22 errata-xmlrpc 2018-04-03 14:21:49 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2018:0630 https://access.redhat.com/errata/RHSA-2018:0630
Comment 23 errata-xmlrpc 2018-04-03 14:34:37 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7

Via RHSA-2018:0628 https://access.redhat.com/errata/RHSA-2018:0628
Comment 24 errata-xmlrpc 2018-04-03 14:36:21 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7
  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5
  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6

Via RHSA-2018:0627 https://access.redhat.com/errata/RHSA-2018:0627
Comment 26 errata-xmlrpc 2018-04-25 14:21:14 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6

Via RHSA-2018:1248 https://access.redhat.com/errata/RHSA-2018:1248
Comment 27 errata-xmlrpc 2018-04-25 14:24:03 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7

Via RHSA-2018:1247 https://access.redhat.com/errata/RHSA-2018:1247
Comment 28 errata-xmlrpc 2018-04-25 14:35:23 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6

Via RHSA-2018:1249 https://access.redhat.com/errata/RHSA-2018:1249
Comment 29 errata-xmlrpc 2018-04-25 15:44:00 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2018:1251 https://access.redhat.com/errata/RHSA-2018:1251
Comment 30 Chess Hazlett 2018-05-02 21:53:58 EDT
SOA-P is reduced (critical only) support, marked WONTFIX
Comment 32 errata-xmlrpc 2018-05-04 10:33:16 EDT
This issue has been addressed in the following products:

  Red Hat Single Sign-On 7.2.2 zip

Via RHSA-2018:1323 https://access.redhat.com/errata/RHSA-2018:1323
Comment 33 errata-xmlrpc 2018-05-14 16:16:32 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2018:1447 https://access.redhat.com/errata/RHSA-2018:1447
Comment 34 errata-xmlrpc 2018-05-14 16:34:56 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7

Via RHSA-2018:1448 https://access.redhat.com/errata/RHSA-2018:1448
Comment 35 errata-xmlrpc 2018-05-14 16:39:17 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6

Via RHSA-2018:1449 https://access.redhat.com/errata/RHSA-2018:1449
Comment 36 errata-xmlrpc 2018-05-14 16:43:32 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5

Via RHSA-2018:1450 https://access.redhat.com/errata/RHSA-2018:1450
Comment 37 errata-xmlrpc 2018-05-14 16:51:17 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6

Via RHSA-2018:1451 https://access.redhat.com/errata/RHSA-2018:1451
Comment 38 errata-xmlrpc 2018-05-15 14:59:03 EDT
This issue has been addressed in the following products:

  Red Hat Virtualization 4 for RHEL-7

Via RHSA-2018:1525 https://access.redhat.com/errata/RHSA-2018:1525
Comment 39 errata-xmlrpc 2018-05-16 11:44:58 EDT
This issue has been addressed in the following products:

  Red Hat Data Grid

Via RHSA-2018:1575 https://access.redhat.com/errata/RHSA-2018:1575
Comment 42 errata-xmlrpc 2018-07-05 11:28:24 EDT
This issue has been addressed in the following products:

  Red Hat Decision Manager

Via RHSA-2018:2143 https://access.redhat.com/errata/RHSA-2018:2143
Comment 43 errata-xmlrpc 2018-08-15 03:41:44 EDT
This issue has been addressed in the following products:

  Red Hat Process Automation

Via RHSA-2018:2419 https://access.redhat.com/errata/RHSA-2018:2419
Comment 44 errata-xmlrpc 2018-08-15 03:42:01 EDT
This issue has been addressed in the following products:

  Red Hat Decision Manager

Via RHSA-2018:2420 https://access.redhat.com/errata/RHSA-2018:2420
Comment 45 errata-xmlrpc 2018-08-15 03:42:48 EDT
This issue has been addressed in the following products:

  Red Hat Decision Manager

Via RHSA-2018:2420 https://access.redhat.com/errata/RHSA-2018:2420
Comment 46 errata-xmlrpc 2018-09-11 03:54:11 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Fuse

Via RHSA-2018:2669 https://access.redhat.com/errata/RHSA-2018:2669
Comment 47 errata-xmlrpc 2018-10-16 13:05:52 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Operations Network

Via RHSA-2018:2930 https://access.redhat.com/errata/RHSA-2018:2930

Note You need to log in before you can comment on or make changes to this bug.