RHSA-2021:2755MediumCVSS 8.1

Red Hat Security Advisory: EAP XP 2 security update to CVE fixes in the EAP 7.3.x base

Published
July 15, 2021
Last Modified
August 4, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2020-13936 — velocity: arbitrary code execution when attacker is able to modify templates CVE-2020-15522 — bouncycastle: Timing issue within the EC math library CVE-2020-28052 — bouncycastle: password bypass in OpenBSDBCrypt.checkPassword utility possible CVE-2021-3536 — wildfly: XSS via admin console when creating roles in domain mode CVE-2021-20220 — undertow: Possible regression in fix for CVE-2020-10687 CVE-2021-20250 — wildfly: Information disclosure due to publicly accessible privileged actions in JBoss EJB Client CVE-2021-21290 — netty: Information disclosure via the local system temporary directory CVE-2021-21295 — netty: possible request smuggling in HTTP/2 due missing validation CVE-2021-21409 — netty: Request smuggling via content-length header

🎯 Affected products1

  • Red Hat EAP-XP 2.0.0 via EAP 7.3.x base

✅ Remediation

This advisory is informational only. There are no code changes associated with it. No action is required. Workaround: Users unable to upgrade to version 1.67 or greater can copy the `OpenBSDBCrypt.doCheckPassword()` method implementation (https://github.com/bcgit/bc-java/blob/r1rv67/core/src/main/java/org/bouncycastle/crypto/generators/OpenBSDBCrypt.java#L259-L343) into their own utility class and supplement it with the required methods and variables as required

🔗 References (15)