RHSA-2021:2051MediumCVSS 6.6

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.3.7 security update

Published
May 19, 2021
Last Modified
August 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2020-13936 — velocity: arbitrary code execution when attacker is able to modify templates CVE-2021-21290 — netty: Information disclosure via the local system temporary directory CVE-2021-21295 — netty: possible request smuggling in HTTP/2 due missing validation

🎯 Affected products1

  • Red Hat JBoss Enterprise Application Platform 7

✅ Remediation

Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. The References section of this erratum contains a download link (you must log in to download the update). The JBoss server process must be restarted for the update to take effect.

🔗 References (30)