RHSA-2021:3660HighCVSS 7.5

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.1 security update

Published
September 23, 2021
Last Modified
August 4, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2020-13936 — velocity: arbitrary code execution when attacker is able to modify templates CVE-2021-3536 — wildfly: XSS via admin console when creating roles in domain mode CVE-2021-3597 — undertow: HTTP2SourceChannel fails to write final frame under some circumstances may lead to DoS CVE-2021-3642 — wildfly-elytron: possible timing attack in ScramServer CVE-2021-3644 — wildfly-core: Invalid Sensitivity Classification of Vault Expression CVE-2021-3690 — undertow: buffer leak on incoming websocket PONG message may lead to DoS CVE-2021-21409 — netty: Request smuggling via content-length header CVE-2021-28170 — jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate CVE-2021-29425 — apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6

🎯 Affected products1

  • Red Hat JBoss Enterprise Application Platform 7

✅ Remediation

Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. The References section of this erratum contains a download link (you must log in to download the update).

🔗 References (41)