Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.3.9 security update on RHEL 8
🔗 CVE IDs covered (5)
📋 Description
CVE-2021-3597 — undertow: HTTP2SourceChannel fails to write final frame under some circumstances may lead to DoS CVE-2021-3644 — wildfly-core: Invalid Sensitivity Classification of Vault Expression CVE-2021-3690 — undertow: buffer leak on incoming websocket PONG message may lead to DoS CVE-2021-28170 — jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate CVE-2021-29425 — apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6
🎯 Affected products79
- Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-apache-commons-io-0:2.10.0-1.redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-apache-commons-io-0:2.10.0-1.redhat_00001.1.el8eap.src as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-hal-console-0:3.2.16-1.Final_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-hal-console-0:3.2.16-1.Final_redhat_00001.1.el8eap.src as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-hibernate-0:5.3.20-4.SP2_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-hibernate-0:5.3.20-4.SP2_redhat_00001.1.el8eap.src as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-hibernate-core-0:5.3.20-4.SP2_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-hibernate-entitymanager-0:5.3.20-4.SP2_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-hibernate-envers-0:5.3.20-4.SP2_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-hibernate-java8-0:5.3.20-4.SP2_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-ironjacamar-0:1.4.35-1.Final_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-ironjacamar-0:1.4.35-1.Final_redhat_00001.1.el8eap.src as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-ironjacamar-common-api-0:1.4.35-1.Final_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-ironjacamar-common-impl-0:1.4.35-1.Final_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-ironjacamar-common-spi-0:1.4.35-1.Final_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-ironjacamar-core-api-0:1.4.35-1.Final_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-ironjacamar-core-impl-0:1.4.35-1.Final_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-ironjacamar-deployers-common-0:1.4.35-1.Final_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-ironjacamar-jdbc-0:1.4.35-1.Final_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-ironjacamar-validator-0:1.4.35-1.Final_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-jakarta-el-0:3.0.3-2.redhat_00006.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-jakarta-el-0:3.0.3-2.redhat_00006.1.el8eap.src as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-jberet-0:1.3.9-1.Final_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-jberet-0:1.3.9-1.Final_redhat_00001.1.el8eap.src as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-jberet-core-0:1.3.9-1.Final_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-jboss-remoting-0:5.0.23-2.SP1_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-jboss-remoting-0:5.0.23-2.SP1_redhat_00001.1.el8eap.src as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-jboss-server-migration-0:1.7.2-9.Final_redhat_00010.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- eap7-jboss-server-migration-0:1.7.2-9.Final_redhat_00010.1.el8eap.src as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
- +49 more not shown
✅ Remediation
Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (25)
- selfhttps://access.redhat.com/errata/RHSA-2021:3468
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.3/
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.3/html-single/installation_guide/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1948752
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1965497
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1970930
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1976052
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1991299
- externalhttps://issues.redhat.com/browse/JBEAP-21466
- externalhttps://issues.redhat.com/browse/JBEAP-21468
- externalhttps://issues.redhat.com/browse/JBEAP-21958
- externalhttps://issues.redhat.com/browse/JBEAP-22003
- externalhttps://issues.redhat.com/browse/JBEAP-22029
- externalhttps://issues.redhat.com/browse/JBEAP-22079
- externalhttps://issues.redhat.com/browse/JBEAP-22085
- externalhttps://issues.redhat.com/browse/JBEAP-22138
- externalhttps://issues.redhat.com/browse/JBEAP-22159
- externalhttps://issues.redhat.com/browse/JBEAP-22195
- externalhttps://issues.redhat.com/browse/JBEAP-22198
- externalhttps://issues.redhat.com/browse/JBEAP-22200
- externalhttps://issues.redhat.com/browse/JBEAP-22204
- externalhttps://issues.redhat.com/browse/JBEAP-22227
- externalhttps://issues.redhat.com/browse/JBEAP-22317
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_3468.json