Bug 1824301 (CVE-2020-1954) - CVE-2020-1954 cxf: JMX integration is vulnerable to a MITM attack
Summary: CVE-2020-1954 cxf: JMX integration is vulnerable to a MITM attack
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2020-1954
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1824302
Blocks: 1824303
TreeView+ depends on / blocked
 
Reported: 2020-04-15 18:44 UTC by Guilherme de Almeida Suckevicz
Modified: 2021-03-04 13:38 UTC (History)
63 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2020-08-31 19:17:29 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2020:3585 0 None None None 2020-08-31 15:41:13 UTC
Red Hat Product Errata RHSA-2020:4244 0 None None None 2020-10-13 16:48:12 UTC
Red Hat Product Errata RHSA-2020:4245 0 None None None 2020-10-13 16:52:20 UTC
Red Hat Product Errata RHSA-2020:4246 0 None None None 2020-10-13 16:56:42 UTC
Red Hat Product Errata RHSA-2020:4247 0 None None None 2020-10-13 17:01:35 UTC
Red Hat Product Errata RHSA-2020:4931 0 None None None 2020-11-04 19:24:25 UTC
Red Hat Product Errata RHSA-2020:4960 0 None None None 2020-11-05 18:47:35 UTC
Red Hat Product Errata RHSA-2020:4961 0 None None None 2020-11-05 18:49:03 UTC

Description Guilherme de Almeida Suckevicz 2020-04-15 18:44:07 UTC
Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory’ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.

Reference:
http://cxf.apache.org/security-advisories.data/CVE-2020-1954.txt.asc?version=1&modificationDate=1585730169000&api=v2

Comment 1 Guilherme de Almeida Suckevicz 2020-04-15 18:44:31 UTC
Created cxf tracking bugs for this issue:

Affects: fedora-30 [bug 1824302]

Comment 8 errata-xmlrpc 2020-08-31 15:41:10 UTC
This issue has been addressed in the following products:

  EAP-CD 20 Tech Preview

Via RHSA-2020:3585 https://access.redhat.com/errata/RHSA-2020:3585

Comment 9 Product Security DevOps Team 2020-08-31 19:17:29 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2020-1954

Comment 10 errata-xmlrpc 2020-10-13 16:48:18 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6

Via RHSA-2020:4244 https://access.redhat.com/errata/RHSA-2020:4244

Comment 11 errata-xmlrpc 2020-10-13 16:52:16 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8

Via RHSA-2020:4245 https://access.redhat.com/errata/RHSA-2020:4245

Comment 12 errata-xmlrpc 2020-10-13 16:56:39 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7

Via RHSA-2020:4246 https://access.redhat.com/errata/RHSA-2020:4246

Comment 13 errata-xmlrpc 2020-10-13 17:01:31 UTC
This issue has been addressed in the following products:

  EAP 7.3.3

Via RHSA-2020:4247 https://access.redhat.com/errata/RHSA-2020:4247

Comment 14 errata-xmlrpc 2020-11-04 19:24:22 UTC
This issue has been addressed in the following products:

  Red Hat Single Sign-On 7.4.3

Via RHSA-2020:4931 https://access.redhat.com/errata/RHSA-2020:4931

Comment 15 errata-xmlrpc 2020-11-05 18:47:32 UTC
This issue has been addressed in the following products:

  RHDM 7.9.0

Via RHSA-2020:4960 https://access.redhat.com/errata/RHSA-2020:4960

Comment 16 errata-xmlrpc 2020-11-05 18:48:59 UTC
This issue has been addressed in the following products:

  RHPAM 7.9.0

Via RHSA-2020:4961 https://access.redhat.com/errata/RHSA-2020:4961


Note You need to log in before you can comment on or make changes to this bug.