RHSA-2021:0495MediumCVSS 7.5

Red Hat Security Advisory: Red Hat JBoss Web Server 5.4.1 Security Update

Published
February 11, 2021
Last Modified
August 4, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2020-1971 — openssl: EDIPARTYNAME NULL pointer de-reference CVE-2020-13943 — tomcat: Apache Tomcat HTTP/2 Request mix-up CVE-2020-17527 — tomcat: HTTP/2 request header mix-up CVE-2021-24122 — tomcat: Information disclosure when using NTFS file system

🎯 Affected products1

  • Red Hat JBoss Web Server 5

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link for the update. You must be logged in to download the update. Workaround: Applications not using the GENERAL_NAME_cmp of openssl are not vulnerable to this flaw. Even when this function is used, if the attacker can control both the arguments of this function, only then the attacker could trigger a crash.

🔗 References (9)