Red Hat Security Advisory: eap7-jboss-ec2-eap security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2014-9970 — jasypt: Vulnerable to timing attack against the password hash comparison CVE-2015-6644 — bouncycastle: Information disclosure in GCMBlockCipher CVE-2017-2582 — keycloak: SAML request parser replaces special strings with system properties CVE-2017-5645 — log4j: Socket receiver deserialization vulnerability CVE-2017-7536 — hibernate-validator: Privilege escalation when running under the security manager CVE-2019-17571 — log4j: deserialization of untrusted data in SocketServer
🎯 Affected products8
- Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server
- Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-jboss-ec2-eap-0:7.0.8-1.GA_redhat_1.ep7.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server
- eap7-jboss-ec2-eap-0:7.0.8-1.GA_redhat_1.ep7.el6.src as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server
- eap7-jboss-ec2-eap-0:7.0.8-1.GA_redhat_1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-jboss-ec2-eap-0:7.0.8-1.GA_redhat_1.ep7.el7.src as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-jboss-ec2-eap-samples-0:7.0.8-1.GA_redhat_1.ep7.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server
- eap7-jboss-ec2-eap-samples-0:7.0.8-1.GA_redhat_1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
✅ Remediation
Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Please note that the Log4j upstream strongly recommends against using the SerializedLayout with the SocketAppenders. Customers may mitigate this issue by removing the SocketServer class outright; or if they must continue to use SocketAppenders, they can modify their SocketAppender configuration from SerializedLayout to use JsonLayout instead. An example of this in log4j-server.properties might look like this: log4j.appender.file.layout=org.apache.log4j.JsonLayout
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2017:2811
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en/red-hat-jboss-enterprise-application-platform/version-7.0/
- externalhttps://access.redhat.com/documentation/en/red-hat-jboss-enterprise-application-platform/version-7.0/installation-guide/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1410481
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1443635
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1444015
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1455566
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1465573
- externalhttps://issues.redhat.com/browse/JBEAP-11487
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2017/rhsa-2017_2811.json