Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 5.2 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2017-5645 — log4j: Socket receiver deserialization vulnerability CVE-2019-17571 — log4j: deserialization of untrusted data in SocketServer
🎯 Affected products6
- Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 Server
- Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 Server
- log4j-0:1.2.14-19.patch_01.ep5.el5.noarch as a component of Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 Server
- log4j-0:1.2.14-19.patch_01.ep5.el5.src as a component of Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 Server
- log4j-0:1.2.14-19.patch_01.ep5.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 Server
- log4j-0:1.2.14-19.patch_01.ep5.el6.src as a component of Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 Server
✅ Remediation
Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Please note that the Log4j upstream strongly recommends against using the SerializedLayout with the SocketAppenders. Customers may mitigate this issue by removing the SocketServer class outright; or if they must continue to use SocketAppenders, they can modify their SocketAppender configuration from SerializedLayout to use JsonLayout instead. An example of this in log4j-server.properties might look like this: log4j.appender.file.layout=org.apache.log4j.JsonLayout
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2017:3399
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1443635
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2017/rhsa-2017_3399.json