Vulnerability in embedded resteasy-jaxrs for Camunda 

Issue date: 27-10-2020
Affects versions: 14.2, 13.4, 12.6

Issue ID: SECURITY-168

Affected Product Version(s)
14.2.2, 13.4.3, 12.6.10 (and previous patch releases)

Severity 
low

Description

The resteasy-jaxrs version embedded in the Camunda engine, and used by the brXM projects feature, had a reported vulnerability that could allow improper behavior in response to a malicious HTTP request. This function was not exposed by the brXM product directly, but could have been used by a customer project.

See: CVE-2020-1695

The resteasy-jaxrs library has now been updated across all our latest supported versions: 14.3.0, 13.4.4 and 12.6.11.

Instructions

Customers are recommended to upgrade to the latest maintenance or minor releases as indicated above. This can be done by simply incrementing the version number of the parent POM for the implementation project.