- Issued:
- 2019-07-25
- Updated:
- 2019-07-25
RHBA-2019:1858 - Bug Fix Advisory
Synopsis
Red Hat OpenShift Application Runtimes Spring Boot update
Type/Severity
Bug Fix Advisory
Topic
An update is available for Red Hat OpenShift Application Runtimes.
Description
Red Hat OpenShift Application Runtimes provides an application platform that reduces the complexity of developing and operating applications (monoliths and microservices) for OpenShift as a containerized platform.
This release of RHOAR Spring Boot 2.1.6 serves as a replacement for RHOAR Spring Boot 2.1.3, and includes security and bug fixes and enhancements. For more information, see the release notes linked to in the References section.
The release also addresses a Spring Boot vulnerability:
cve-2019-11269: Open Redirector in spring-security-oauth2
Solution
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.
The References section of this erratum contains a download link (you must log in to download the update).
Affected Products
- Red Hat Openshift Application Runtimes Text-Only Advisories x86_64
Fixes
(none)CVEs
(none)
References
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=catRhoar.spring.boot&downloadType=distributions&version=2.1.6
- https://access.redhat.com/documentation/en-us/red_hat_openshift_application_runtimes/1/html-single/rhoar_spring_boot_2.1.x_release_notes
- https://pivotal.io/security/cve-2019-11269
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.