RHSA-2020:3626MediumCVSS 8.4

Red Hat Security Advisory: Red Hat Data Grid 8.1.0 Security Update

Published
September 3, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2020-9488 — log4j: improper validation of certificate with host mismatch in SMTP appender CVE-2020-10746 — Infinispan: REST and HotRod APIs unsecured locally by default CVE-2020-11612 — netty: compression/decompression codecs don't enforce limits on buffer allocation sizes

🎯 Affected products1

  • Red Hat Data Grid

✅ Remediation

Refer to the Data Grid 8.1 Upgrade Guide for instructions on upgrading to this version. The References section of this erratum contains a download link (you must log in to download the update). Workaround: Previous versions can set the system property mail.smtp.ssl.checkserveridentity to true to globally enable hostname verification for SMTPS connections.

🔗 References (8)