This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Apache updates/advisories

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

Apache Commons Collections Java library insecurely deserializes data
- https://blogs.oracle.com/security/entry/security_alert_cve_2015_4852
Nov 10, 2015 - "This Security Alert addresses security issue CVE-2015-4852, a deserialization vulnerability involving Apache Commons and Oracle WebLogic Server. This is a remote code execution vulnerability and is remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password…"
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-4852

- http://www.oracle.com/technetwork/topics/security/alert-cve-2015-4852-2763333.html
"… Due to the severity of this vulnerability, Oracle strongly recommends that customers apply the updates provided by this Security Alert as soon as possible…"
2015-Nov-12 - Rev 2. Versions Updated
> http://www.oracle.com/technetwork/topics/security/alert-cve-2015-4852-verbose-2763334.html#FMW

> https://www.kb.cert.org/vuls/id/576313
Last revised: 15 Dec 2015

 

> https://commons.apache.org/proper/commons-collections/download_collections.cgi
Last Published: 14 Nov 2015

- https://cxf.apache.org/security-advisories.html

- http://www.securitytracker.com/id/1034097
CVE Reference: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-4852
Updated: Nov 16 2015
Impact: A remote user can execute arbitrary code on the target system.
Solution: The vendor has issued a proposed fix, available at:
- http://svn.apache.org/viewvc?view=revision&revision=1713307
The vendor's advisory is available at:
- https://issues.apache.org/jira/browse/COLLECTIONS-580
___

>> https://cxf.apache.org/security-advisories.data/CVE-2015-5253.txt.asc
"… Severity: Major
Migration:
CXF 2.7.x users should upgrade to 2.7.18 or later as soon as possible.
CXF 3.0.x users should upgrade to 3.0.7 or later as soon as possible.
CXF 3.1.x users should upgrade to 3.1.3 or later as soon as possible…"

> http://www.securitytracker.com/id/1034162
CVE Reference: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-5253
Nov 16 2015
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): prior to versions 2.7.18, 3.0.7, 3.1.3 …
Solution: The vendor has issued a fix (2.7.18, 3.0.7, 3.1.3).
 

:ph34r: :ph34r:

FYI…

Apache Tomcat - v6.x, 7.x, 8.x, 9.x / updates released
- https://en.wikipedia.org/wiki/Apache_Tomcat
"Apache Tomcat, often referred to as Tomcat, is an open-source web server developed by the Apache Software Foundation (ASF). Tomcat implements several Java EE specifications including Java Servlet, JavaServer Pages (JSP), Java EL, and WebSocket, and provides a "pure Java" HTTP web server environment for Java code to run in. Tomcat is developed and maintained by an open community of developers under the auspices of the Apache Software Foundation… and is open-source software…
> https://en.wikipedia.org/wiki/Apache_Tomcat#High_availability
A high-availability feature has been added to facilitate the scheduling of system upgrades (e.g. new releases, change requests) without affecting the live environment. This is done by dispatching live traffic requests to a temporary server on a different port while the main server is upgraded on the main port. It is very useful in handling user requests on high-traffic web applications…"
- http://www.securitytracker.com/id/1035069
CVE Reference: CVE-2015-5346, CVE-2015-5351, CVE-2016-0706, CVE-2016-0714, CVE-2016-0763
Feb 22 2016
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 6.x, 7.x, 8.x, 9.x
Impact: A remote user can bypass security controls on the target system.
A remote user can obtain potentially sensitive information on the target system.
A remote user can hijack the target user's session.
Solution: The vendor has issued a fix (6.0.45, 7.0.68, 8.0.32, 9.0.0.M3)…

> https://tomcat.apache.org/
 

:ph34r: :ph34r:

FYI…

Apache Struts - 2.3.32 / 2.5.10.1 released
- https://isc.sans.edu/diary.html?storyid=22169
2017-03-09 - "On Monday, Apache released a patch for the Struts 2 framework [1]. The patch fixes an easy to exploit vulnerability in the multipart parser that is typically used for file uploads. A Metasploit module was released that same day, and some readers reported seeing exploit attempts in the wild.
You should be running Struts 2.3.32 or 2.5.10.1. All prior versions are vulnerable.
Struts 2 is a Java framework that is commonly used by Java-based web applications. It is also knowns as "Jakarta Struts" and "Apache Struts". The Apache project currently maintains Struts. The vulnerability allows an attacker to include code in the "Content-Type" header of an HTTP request. The code will then be executed by the web server…"

1] https://cwiki.apache.org/confluence/display/WW/S2-045
Mar 06, 2017
Maximum security rating: High
"… Upgrade to Struts 2.3.32: https://cwiki.apache.org/confluence/display/WW/Version+Notes+2.3.32
or Struts 2.5.10.1: https://cwiki.apache.org/confluence/display/WW/Version+Notes+2.5.10.1…"

- https://www.us-cert.gov/ncas/current-activity/2017/03/08/Apache-Software-Foundation-Releases-Security-Updates
Mar 08, 2017

- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-5638
Last revised: 03/15/2017 - "… as exploited in the wild in March 2017."

9.8 Critical

- http://www.securitytracker.com/id/1037973
CVE Reference: CVE-2017-5638
Mar 9 2017
Fix Available:  Yes  Vendor Confirmed:  Yes  Exploit Included:  Yes  
Version(s): 2.3.5 - 2.3.31, 2.5 - 2.5.10 …
Impact: A remote user can execute arbitrary operating system commands on the target system.
Solution: The vendor has issued a fix (2.3.32, 2.5.10.1)…
___

- https://threatprotect.qualys.com/2017/03/08/apache-struts-jakarta-multipart-parser-remote-code-execution-vulnerability/
Mar 8, 2017

- https://arstechnica.com/security/2017/03/critical-vulnerability-under-massive-attack-imperils-high-impact-sites/?comments=1&post=32957185
Mar 9, 2017

- http://blog.trendmicro.com/trendlabs-security-intelligence/cve-2017-5638-apache-struts-vulnerability-remote-code-execution/
Mar 9, 2017
 

:ph34r: :ph34r:

FYI…

Apache releases Security Updates
- https://www.us-cert.gov/ncas/current-activity/2017/04/12/Apache-Software-Foundation-Releases-Security-Updates
April 12, 2017 - "The Apache Foundation has released security updates to address vulnerabilities in Apache Tomcat. Exploitation of one of these vulnerabilities may cause a remote attacker to obtain sensitive information. Users and administrators are encouraged to review…"

CVE-2017-5648
> https://mail-archives.us.apache.org/mod_mbox/www-announce/201704.mbox/%[removed]%3e
CVE-2017-5650
> https://mail-archives.us.apache.org/mod_mbox/www-announce/201704.mbox/%[removed]%3e
CVE-2017-5651
> https://mail-archives.us.apache.org/mod_mbox/www-announce/201704.mbox/%[removed]%3e
 

:ph34r: :ph34r: